Which resources can be used as the source for an inbound rule in a Network Security Group?
Choose an answer
Tap an option to check your answer.
Correct answer: IP Addresses, Service tags and Application security groups.
Why this is the answer
Network Security Groups (NSGs) filter network traffic to and from Azure resources. For inbound rules, you can specify the source of the traffic using IP addresses (individual or CIDR blocks), Service Tags (Azure-defined groups of IP prefixes for services like AzureFrontDoor.Backend), or Application Security Groups (ASGs). ASGs allow you to group virtual machines logically and define network security policies based on those groups, simplifying rule management. Therefore, all three options provide flexible ways to define the source for inbound NSG rules. The other options are incorrect because they limit the available source types, whereas NSGs support all three.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed