exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 15 question 1 discussion

Actual exam question from Microsoft's AZ-700
Question #: 1
Topic #: 15
[All AZ-700 Questions]

HOTSPOT -
In which NSGs can you use ASG1 and to which virtual machine network interfaces can you associate ASG1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
leo87las2
Highly Voted 2 years, 1 month ago
NSG1,NSG2 same vnet VM2 only NIC in same Vnet https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups
upvoted 41 times
GBAU
1 year ago
Yep, so NSGs (only in the same region*, West US): NSG1, NSG2 & NSG5 only *Tested in a lab: -ASG in Australia SE -NSG in Australia SE => New inbound rule, source ASG, ASG listed in the drop down box -NSG in SE Asia => New inbound rule, source ASG, NO ASGs listed in the drop down box to select from VM (only in the same vNet**): VM2 only * already assigned to VM1 so limited to Vnet1 https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups "All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in."
upvoted 3 times
danaohara96
1 month, 2 weeks ago
NGS5 was in EastUS not in WestUS
upvoted 1 times
...
...
...
[Removed]
Highly Voted 2 years, 2 months ago
Tested NSG1, NSG2, and NSG5 only : ASG and NSG must be in the same region VM2 only : network interfaces attached to an ASG must be in the same vNet. https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups
upvoted 22 times
somenick
1 year, 7 months ago
NSG1, NSG2, and NSG5 only. Also tested and it's true. You can use ASG from another VNET in the same region.
upvoted 2 times
...
Tanminator
8 months, 1 week ago
Yep! I have tested too.
upvoted 1 times
...
tdienst
2 years, 2 months ago
NSG1 & NSG2 VM2 Only NSG5 also is out of the question: All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group. ref: https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups
upvoted 18 times
GiorgioLDN
2 years ago
Correct. ASG1 is applied on VM1. VM1’s interface is the first network interface assigned to ASG1, thus all subsequent network interfaces assigned to ASG1 must exist in VNet1. NSG2 exists in VNet1.
upvoted 1 times
wooyourdaddy
1 year, 7 months ago
I set up this lab scenario. When I go to NSG5 and create an inbound rule, I am able to change the destination to application security group and ASG1 is visible as an option to select. When I try in NSG3 and NSG4, the Destination application security groups drop down is greyed out and says 'No application security groups found'. When I go to Network under Settings on VM5, the ASG1 application security group is visible as an option to choose. However, when I click save, the operation fails indicating that the ASG is already attached to another device in a separate subnet. I was successfully able to add VM2 to the ASG, but ASG1 was not even visible to VM3 and VM4. The questions seems to want to drive home the point that NSGs and ASGs need to be in the same region if you intend to use the ASG in an NSG rule, while VM NICs added to an ASG need to be in the same VNET.
upvoted 2 times
...
...
[Removed]
1 year, 11 months ago
Please read the question again, and the next paragraph in the link. The question is about connection between ASG and NSG, not between ASG and NIC.
upvoted 1 times
wooyourdaddy
1 year, 7 months ago
I was initially only NSG1 & NSG2 only, but came across these 2 websites: https://medium.com/awesome-azure/azure-application-security-group-asg-1e5e2e5321c3 https://petri.com/understanding-application-security-groups-in-the-azure-portal/ Which both state: Source and Destination in the new rule blade allow you to select any application security group in the same region. So while their may be not practical use case for using ASG1 in NSG5 in this case, the ASG can be selected by any NSGs in the same region. The only caveat being: If you specify an application security group as the source and destination in a security rule, the network interfaces in both application security groups must exist in the same virtual network. So I would agree that NSG1, NSG2 and NSG5 can use ASG1. And only VM2 can be added to ASG1 due to the NICs needing to be in the same VNET.
upvoted 3 times
wooyourdaddy
1 year, 7 months ago
I set up this lab scenario. When I go to NSG5 and create an inbound rule, I am able to change the destination to application security group and ASG1 is visible as an option to select. When I try in NSG3 and NSG4, the Destination application security groups drop down is greyed out and says 'No application security groups found'. When I go to Network under Settings on VM5, the ASG1 application security group is visible as an option to choose. However, when I click save, the operation fails indicating that the ASG is already attached to another device in a separate subnet. I was successfully able to add VM2 to the ASG, but ASG1 was not even visible to VM3 and VM4. The questions seems to want to drive home the point that NSGs and ASGs need to be in the same region if you intend to use the ASG in an NSG rule, while VM NICs added to an ASG need to be in the same VNET.
upvoted 3 times
...
...
...
...
...
bobothewiseman
Most Recent 2 months, 1 week ago
Study hard! 5+ questions for Case study, including this. The hardest part is Simulation NSG1,NSG2 VM2
upvoted 1 times
...
bobothewiseman
3 months, 2 weeks ago
NSG1, NSG2 & NSG5 only VM2 only
upvoted 1 times
...
jayek
9 months ago
https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups#:~:text=All%20network%20interfaces,application%20security%20group.
upvoted 1 times
...
jakubklapka
1 year, 1 month ago
In exam Sep, 2023
upvoted 2 times
...
JohnnyChimpo
1 year, 6 months ago
Congrats on making it to the last question. Godspeed and best of luck everyone :D
upvoted 11 times
...
_fvt
1 year, 7 months ago
- All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group. - If you specify an application security group as the source and destination in a security rule, the network interfaces in both application security groups must exist in the same virtual network. For example, if AsgLogic contained network interfaces from VNet1, and AsgDb contained network interfaces from VNet2, you could not assign AsgLogic as the source and AsgDb as the destination in a rule. All network interfaces for both the source and destination application security groups need to exist in the same virtual network. So, you can apply the ASG to all NSG within the same region : => "NSG1, NSG2, and NSG5 only" But, as VM1 NIC is already in the ASG, you cannot add another NIC from a different VNet: => "VM2 only"
upvoted 1 times
...
Madball
1 year, 9 months ago
I believe the answers are: NSGS = NSG1, NSG2 and NSG5 only. My reasoning for this is that an ASG can be used in NSG rules for any NSG within the same region. Virtual Machines = VM2 only The ASG can only be attached to NICS within the same virtual network. I have tested this in my lab.
upvoted 5 times
...
TJ001
1 year, 9 months ago
Box 1: NSG 1 and NSG 2 Box 2: VM2
upvoted 3 times
...
vivikar
1 year, 10 months ago
NSG 1 and NSG2: As per All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group.
upvoted 1 times
...
winy
1 year, 11 months ago
Box 1: NSG 1 and NSG 2 Box 2: VM2 , VM1 only This has been tested on the LAB. All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group. https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups#allow-database-businesslogic
upvoted 5 times
...
winy
1 year, 11 months ago
Box 1: NSG 1 and NSG 2 Box 2: VM2 All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group. https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups#allow-database-businesslogic
upvoted 2 times
...
Prutser2
2 years ago
box1: only vnets 1 and 4 are in westUS, so only NSGs in this region can re-use the existing ASG1 result: NSG1, NSG2 and NSG5 box2: All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group. source:https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups result:Vm2 only (was already assigned to VM1, which is in vnet1)
upvoted 1 times
...
Pradh
2 years, 1 month ago
These are correct answers !! Rest is your wish to opt for . NSG1, NSG2, and NSG5 only VM2 only
upvoted 2 times
...
Cristoicach91
2 years, 2 months ago
Correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago