Subnet1 is associated to NSG1, which blocks all outbound traffic not explicitly allowed. VMs in Subnet1 must communicate with Azure Cosmos DB. To allow outbound access to Cosmos DB via NSG1, which configuration element should you reference in the outbound security rule?
Choose an answer
Tap an option to check your answer.
Correct answer: a service tag.
Why this is the answer
A service tag is the correct choice because it represents a group of IP address prefixes for a given Azure service, like Azure Cosmos DB. By using the AzureCosmosDB service tag in an outbound security rule for NSG1, you allow traffic to all IP addresses used by Azure Cosmos DB without needing to know or update specific IP ranges. A service endpoint policy is used to filter outbound traffic to Azure services over service endpoints, but it's not the direct mechanism for allowing traffic through an NSG. Subnet delegation allows a specific Azure service to have control over a subnet's lifecycle, but it doesn't directly configure NSG rules for outbound access. An application security group (ASG) groups virtual machines and allows you to define network security policies based on these groups, but it's not designed to represent external Azure services like Cosmos DB.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed