You have a subnet (Subnet1) that contains three virtual machines hosting an application named App1. App1 is accessed over SFTP. In NSG1 you created an inbound security rule named Rule2 that allows SFTP connections to ASG1. You must ensure that inbound SFTP connections are enforced using ASG1 and minimize administrative effort. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: On each virtual machine, associate the network interface with ASG1..
Why this is the answer
Associating each virtual machine's network interface with ASG1 ensures that the inbound SFTP rule (Rule2) in NSG1, which targets ASG1, applies directly to those VMs. This enforces the SFTP connections using the application security group as intended and minimizes administrative effort by managing security at the application level rather than individual IP addresses. Changing the priority of Rule2 in NSG1 would only reorder its evaluation, not connect it to the VMs. Creating a subnet delegation from Subnet1 is used for integrating Azure services with a subnet, not for associating VMs with ASGs. Changing role assignments in ASG1 relates to access control for managing the ASG itself, not for applying network security rules to VMs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed