You have 10 VMs, a Key Vault Vault1, and an NSG named NSG1 that blocks all outbound internet traffic. All resources are in East US. You need the VMs to access Vault1 while using least privilege and minimal effort. What should you set as the destination in NSG1's outbound security rule?
Choose an answer
Tap an option to check your answer.
Correct answer: a service tag.
Why this is the answer
A service tag is the correct choice because it represents a group of IP address prefixes for a given Azure service, like Azure Key Vault. Using the "KeyVault" service tag in an NSG rule allows your VMs to securely communicate with Key Vault without needing to know or update specific IP address ranges, which can change. This approach adheres to the principle of least privilege by only allowing access to the necessary service and minimizes effort as Azure manages the underlying IP addresses. An application security group (ASG) is used to group VMs and define network security policies based on those groups, not for accessing Azure services. An IP address range would be difficult to maintain as Key Vault's IP addresses can change, requiring constant updates and potentially leading to service disruptions or security vulnerabilities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed