A subnet named Subnet1 has VMs and an NSG (NSG1) with only the default rules. You need to add an NSG rule that prevents Subnet1 hosts from connecting to the Azure portal while still allowing connections to other internet hosts. What should the rule's Destination be set to?
Choose an answer
Tap an option to check your answer.
Correct answer: Service Tag.
Why this is the answer
The correct answer is Service Tag. Azure Service Tags represent a group of IP address prefixes for specific Azure services. Using the "AzurePortal" Service Tag as the destination for a Deny outbound rule will block access to the Azure portal from Subnet1, while allowing other internet traffic. IP Addresses would require you to manually list all IP ranges for the Azure portal, which are dynamic and extensive, making it impractical to maintain. Application security group (ASG) is used to group VMs and apply network security rules to them, not to define external service destinations. "Any" would block all outbound internet traffic, not just to the Azure portal.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed