VM1 and VM2 were deployed from the same template and run line-of-business apps. An NSG is configured as shown. You need to block VM1 and VM2 users from reaching websites on the Internet over TCP port 80. What action should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Associate the NSG to Subnet1..
Why this is the answer
Associating the Network Security Group (NSG) to Subnet1 is the correct action because NSGs applied to a subnet filter traffic for all VMs within that subnet. By associating the NSG, its outbound rule to deny TCP port 80 traffic will apply to both VM1 and VM2, effectively blocking their access to websites on the Internet. Disassociating the NSG from a network interface would remove all filtering, not just block port 80. Changing the Port80 inbound rule would affect incoming traffic to the VMs, not outgoing traffic to the Internet. Changing the DenyWebSites outbound rule is unnecessary as the rule is already configured correctly to deny outbound traffic on port 80; the problem is that the NSG isn't yet applied at a scope that affects both VMs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed