You deployed Azure Application Gateway v2 (AppGw1) into Subnet1 of VNet1 and associated a network security group NSG1 to Subnet1. You want AppGw1 to load balance only traffic that originates from resources inside VNet1 while minimizing impact to AppGw1 functionality. Which rule should you add to NSG1?
Choose an answer
Tap an option to check your answer.
Correct answer: an inbound rule that has a priority of 4096 and blocks all internet traffic.
Why this is the answer
The correct answer is an inbound rule with a priority of 4096 that blocks all internet traffic. Application Gateway v2 requires outbound internet connectivity for management and health probes, so an outbound rule blocking internet traffic would break its functionality. Inbound internet traffic, however, is not strictly necessary for the Application Gateway to load balance internal VNet1 traffic. By blocking inbound internet traffic with a low-priority rule (high number, like 4096), you ensure that any necessary default or higher-priority inbound rules for internal VNet1 communication are still processed, while explicitly preventing external internet access. A priority of 100 is too low and might override essential default rules.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed