As you plan App1's migration, you create a network security group (NSG). What configuration do you recommend so users can access App1?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an inbound security rule allowing port 443 from the Internet and associate the NSG to the subnet containing the web servers.
Why this is the answer
To allow users to access App1, which is a web application, an inbound security rule is necessary. Users initiate connections to the web servers, so the rule must permit traffic into the network. Web traffic typically uses port 443 for HTTPS, making it the correct port to open. The source of this traffic is the "Internet," meaning any external IP address. Associating the NSG to the subnet containing only the web servers ensures that the rule applies specifically to the resources that need it, following the principle of least privilege and avoiding unnecessary exposure of other subnets. Outbound rules (incorrect options) control traffic leaving the network, which is not relevant for users accessing the application. Associating the NSG to "all subnets" (incorrect options) is overly permissive and less secure than targeting only the necessary subnet.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed