Your Azure environment has multiple virtual machines. You must make VM1 accessible from the Internet over HTTP. Which two solutions would accomplish this? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
Choose an answer
Tap an option to check your answer.
Correct answer: Modify a network security group (NSG), Modify an Azure firewall.
Why this is the answer
Modifying a network security group (NSG) is correct because NSGs filter network traffic to and from Azure resources. To allow HTTP access to VM1, you would add an inbound security rule to the NSG associated with VM1's network interface or subnet, permitting traffic on port 80 (HTTP) from the internet. Modifying an Azure Firewall is also correct because Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources. You can configure an application rule or network rule in the Azure Firewall to allow inbound HTTP traffic to VM1 from the internet. Modifying an Azure Traffic Manager profile is incorrect because Traffic Manager is a DNS-based traffic load balancer that distributes traffic across multiple endpoints. It doesn't provide direct network access control or firewall capabilities. Modifying a DDoS protection plan is incorrect because Azure DDoS Protection safeguards Azure resources from distributed denial-of-service attacks. It does not control standard inbound network access for specific protocols like HTTP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed