You are planning to deploy many web servers and database servers to Azure. The design must allow control over the types of connections between the web servers and the database servers. Solution: you include network security groups (NSGs). Does this solution meet the goal?
Choose an answer
Tap an option to check your answer.
Correct answer: Yes.
Why this is the answer
Yes, this solution meets the goal. Network Security Groups (NSGs) are used to filter network traffic to and from Azure resources in an Azure Virtual Network. They allow you to define rules that permit or deny communication based on source/destination IP address, port, and protocol. By applying NSGs to subnets containing your web servers and database servers, or directly to the network interfaces of these servers, you can precisely control which connections are allowed between them, thereby enforcing your desired network security policy. Other Azure networking components like Virtual Networks (VNet) provide the isolated network space but not the granular traffic filtering, and Azure Firewall offers more advanced, centralized protection but NSGs are sufficient and often preferred for controlling traffic within a VNet between specific server roles.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed