Application Security Group for Dynamic Scaling
A team manages 20 web VMs and 15 app VMs that scale independently. The administrator needs an NSG rule that allows only the web tier to reach the app tier on TCP 8443, and future VM additions must be included automatically without editing IP addresses. What should the administrator use in the NSG rule?
Quick Answer
The answer is to use a source application security group for the web tier and a destination application security group for the app tier. This configuration is correct because application security groups (ASGs) enable dynamic scaling by allowing you to define NSG rules based on logical VM groupings rather than static IP addresses. When new VMs are added to either the web or app ASG during scaling events, the NSG rule automatically applies to them without any manual IP edits, perfectly meeting the requirement for future VM inclusion. On the AZ-104 exam, this scenario tests your understanding of how ASGs decouple network security from infrastructure changes, often appearing as a trap where candidates mistakenly choose service tags or traditional IP-based rules. A helpful memory tip: think of ASGs as "security tags for your VM teams" — if the VMs are on the same team, the rule follows them automatically, no matter how many new players join.
⚠ Common exam trap
Candidates often confuse ASGs with network security groups (NSGs) themselves or think that service endpoints or UDRs can provide application-layer filtering, when in fact only ASGs enable IP-agnostic, dynamic grouping for NSG rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A source application security group for the web tier and a destination application security group for the app tier.
Application security groups (ASGs) allow you to define network security rules based on logical groupings of VMs, regardless of their IP addresses. By assigning the web tier VMs to a source ASG and the app tier VMs to a destination ASG, the NSG rule automatically includes any new VMs added to those groups, meeting the requirement for dynamic inclusion without manual IP edits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A source application security group for the web tier and a destination application security group for the app tier.
Why this is correct
Application security groups let you group VMs by function rather than by individual IP addresses. An NSG rule can reference a source ASG and a destination ASG, so newly added web or app VMs are automatically governed as long as they are added to the correct ASG. This is ideal for scalable tier-to-tier access control.
- ✗
A service endpoint on the subnet where the app VMs are deployed.
Why it's wrong here
Service endpoints are for securing access to supported Azure PaaS services, not for defining VM-to-VM security groups inside a virtual network.
When this WOULD be correct
An administrator needs to ensure that VMs in a subnet can only access an Azure SQL Database instance, and all traffic must go through the Azure backbone network. A service endpoint on the subnet would be the correct choice.
- ✗
A user-defined route between the web subnet and app subnet.
Why it's wrong here
Routes control packet forwarding paths, but they do not provide access control or automatically manage group membership for allowed sources and destinations.
When this WOULD be correct
A UDR would be correct if the question required traffic between the web and app subnets to be routed through a network virtual appliance (NVA) for inspection, e.g., 'Force traffic from web subnet to app subnet to go through a firewall.'
- ✗
A load balancer backend pool for both tiers.
Why it's wrong here
Backend pools are used for load balancing traffic, not for expressing security policy between application tiers.
When this WOULD be correct
An administrator needs to distribute incoming traffic from the internet to a set of VMs in a backend pool and ensure high availability. The load balancer would be the correct answer for distributing traffic, not for NSG filtering.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓A source application security group for the web tier and a destination application security group for the app tier.Correct answer▾
Why this is correct
Application security groups let you group VMs by function rather than by individual IP addresses. An NSG rule can reference a source ASG and a destination ASG, so newly added web or app VMs are automatically governed as long as they are added to the correct ASG. This is ideal for scalable tier-to-tier access control.
✗A service endpoint on the subnet where the app VMs are deployed.Wrong answer — click to see why▾
Why this is wrong here
Service endpoints secure Azure service access (e.g., Azure Storage) from a subnet, not traffic between VMs. They cannot restrict traffic between web and app tiers based on application security groups.
★ When this WOULD be the correct answer
An administrator needs to ensure that VMs in a subnet can only access an Azure SQL Database instance, and all traffic must go through the Azure backbone network. A service endpoint on the subnet would be the correct choice.
Why candidates choose this
Candidates may confuse service endpoints with network security groups, thinking they can control VM-to-VM traffic, or they may believe endpoints can replace NSG rules for inter-tier communication.
✗A user-defined route between the web subnet and app subnet.Wrong answer — click to see why▾
Why this is wrong here
A user-defined route (UDR) controls network traffic routing between subnets, not security filtering. It cannot allow or deny traffic based on port or application; NSG rules are required for that purpose.
★ When this WOULD be the correct answer
A UDR would be correct if the question required traffic between the web and app subnets to be routed through a network virtual appliance (NVA) for inspection, e.g., 'Force traffic from web subnet to app subnet to go through a firewall.'
Why candidates choose this
Candidates may confuse routing with security, thinking that directing traffic between subnets via a UDR can also enforce access control, especially when the question mentions 'allow only the web tier to reach the app tier.'
✗A load balancer backend pool for both tiers.Wrong answer — click to see why▾
Why this is wrong here
A load balancer backend pool groups VMs for traffic distribution, not for NSG rule source/destination specification. It cannot be used as a source or destination in an NSG rule to filter traffic between tiers.
★ When this WOULD be the correct answer
An administrator needs to distribute incoming traffic from the internet to a set of VMs in a backend pool and ensure high availability. The load balancer would be the correct answer for distributing traffic, not for NSG filtering.
Why candidates choose this
Candidates may confuse the grouping capability of a load balancer backend pool with the grouping capability of an application security group, thinking both can be used to define traffic sources/destinations in NSG rules.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
NSG rule
An NSG rule is a set of security rules in Microsoft Azure that controls whether network traffic is allowed or denied to and from Azure resources.
Key term
Network security
Network security is the practice of protecting a computer network from unauthorized access, misuse, malfunction, modification, destruction, or improper disclosure, ensuring the confidentiality, integrity, and availability of data and resources.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-104
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A three-tier application uses separate web and app VMs. The requirement is to allow only the web tier to reach the app tier on TCP 8080. The app subnet NSG already contains a DenyAllInbound rule at priority 200. What should the administrator do?
medium- ✓ A.Create an inbound allow rule for the web ASG to the app ASG on TCP 8080 with priority 150.
- B.Move the DenyAllInbound rule to priority 300 so all traffic is blocked first.
- C.Add a user-defined route from the web subnet to the app subnet.
- D.Associate the web and app NICs with the same application security group.
Why A: The existing DenyAllInbound rule at priority 200 will block all traffic to the app subnet unless a higher-priority (lower number) allow rule is created. By creating an inbound allow rule for the web Application Security Group (ASG) to the app ASG on TCP 8080 with priority 150, the administrator ensures that traffic from the web tier is explicitly permitted before the deny rule is evaluated, satisfying the requirement.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.