Courseiva

Understanding NSG Rule Priority: Allow vs Deny

A VM in Azure cannot accept RDP connections from your office public IP. The subnet NSG already has an inbound deny-all rule at priority 200, and you added an allow rule for TCP 3389 from 198.51.100.25/32 at priority 300. What should you do to allow the connection?

⚠ Common exam trap

The trap here is that candidates mistakenly think adding a more specific allow rule at a higher priority number will override a broader deny rule, not realizing that NSG priority order (lower number = higher priority) determines which rule is evaluated first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create or move the allow rule to priority 100 so it is evaluated before the deny rule.

Network Security Group (NSG) rules are evaluated in priority order, with lower numbers having higher precedence. Since the deny-all rule at priority 200 is evaluated before the allow rule at priority 300, the deny rule blocks the RDP traffic. To allow the connection, the allow rule must be created or moved to a priority lower than 200 (e.g., 100) so it is evaluated first, permitting traffic from 198.51.100.25/32 on TCP 3389 before the deny rule is reached.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the source to Internet so the allow rule matches more traffic.

    Why it's wrong here

    Changing the source to Internet broadens the matching scope, but priority dictates which rule acts on traffic. A deny-all rule with a numerically lower priority (higher importance) will still match first and block the RDP attempt, so the allow rule never gets evaluated. This also removes IP-based restricting, allowing any public address to attempt connection, creating a security risk without fixing the connectivity issue.

    When this WOULD be correct

    In a scenario where the NSG has no lower-priority deny rule blocking specific IPs, and you need to allow RDP from any public IP (e.g., for a jump server accessible from anywhere), setting the source to 'Internet' would be appropriate.

  • ✓

    Create or move the allow rule to priority 100 so it is evaluated before the deny rule.

    Why this is correct

    NSG rules are evaluated in ascending priority order, meaning numeric 100 takes precedence over a higher-numbered deny rule such as 4096. By placing an allow rule for RDP (port 3389) from your office IP at priority 100, it is processed first and matches before the deny-all rule, permitting the connection. This is the standard method for overriding a broad deny rule while keeping security boundaries intact.

  • ✗

    Change the protocol from TCP to Any to bypass the deny rule.

    Why it's wrong here

    Changing the protocol from TCP to Any affects the protocol match parameters, not the rule processing sequence. The deny-all rule at priority 4096 is still evaluated before any lower-priority allow rule, so even an allow rule covering Any protocol will never be reached. In fact, broadening protocol scope wastes effort because the deny rule still wins solely based on priority.

    When this WOULD be correct

    If the question described a scenario where the NSG allow rule for RDP uses TCP but the actual traffic uses a different protocol (e.g., UDP), then changing the protocol to Any could allow the connection. For example, if a VM requires RDP over UDP and the NSG only allows TCP, setting the protocol to Any would match both.

  • ✗

    Assign a public IP directly to the VM to override the subnet NSG behavior.

    Why it's wrong here

    Assigning a public IP to the VM's NIC merely exposes the VM to the internet; it does not alter NSG evaluation. Traffic still enters the subnet and is filtered by subnet and NIC NSGs in priority order, so the existing deny-all rule with a lower priority value (e.g., 4096) still blocks port 3389. In fact, adding a public IP can increase attack surface without changing rule evaluation.

    When this WOULD be correct

    This would be correct if the VM is in a subnet without an NSG (or with an allow-all rule) but the VM's NIC has no public IP, and you need to enable inbound RDP from the internet by assigning a public IP and adding an NSG rule on the NIC.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

✓Create or move the allow rule to priority 100 so it is evaluated before the deny rule.Correct answer▾

Why this is correct

NSG rules are evaluated in ascending priority order, meaning numeric 100 takes precedence over a higher-numbered deny rule such as 4096. By placing an allow rule for RDP (port 3389) from your office IP at priority 100, it is processed first and matches before the deny-all rule, permitting the connection. This is the standard method for overriding a broad deny rule while keeping security boundaries intact.

✗Change the source to Internet so the allow rule matches more traffic.Wrong answer — click to see why▾

Why this is wrong here

Changing the source to 'Internet' would allow traffic from all public IPs, not just your office IP, which violates the principle of least privilege and does not fix the rule priority issue. The deny rule at priority 200 still blocks the traffic because the allow rule at priority 300 is evaluated after it.

★ When this WOULD be the correct answer

In a scenario where the NSG has no lower-priority deny rule blocking specific IPs, and you need to allow RDP from any public IP (e.g., for a jump server accessible from anywhere), setting the source to 'Internet' would be appropriate.

Why candidates choose this

Candidates may think that broadening the source scope will override the deny rule, misunderstanding that NSG rules are evaluated in priority order and a lower-priority allow rule cannot override a higher-priority deny rule.

✗Change the protocol from TCP to Any to bypass the deny rule.Wrong answer — click to see why▾

Why this is wrong here

Changing the protocol to Any would not bypass the deny rule; the deny rule at priority 200 still blocks all inbound traffic regardless of protocol. The issue is rule priority, not protocol matching.

★ When this WOULD be the correct answer

If the question described a scenario where the NSG allow rule for RDP uses TCP but the actual traffic uses a different protocol (e.g., UDP), then changing the protocol to Any could allow the connection. For example, if a VM requires RDP over UDP and the NSG only allows TCP, setting the protocol to Any would match both.

Why candidates choose this

Candidates may think that broadening the protocol match will override the deny rule, misunderstanding that NSG rules are evaluated by priority order, not by specificity or protocol coverage.

✗Assign a public IP directly to the VM to override the subnet NSG behavior.Wrong answer — click to see why▾

Why this is wrong here

Assigning a public IP to the VM does not override subnet NSG rules; NSGs at both subnet and NIC levels are still evaluated, and the deny rule at priority 200 would still block RDP traffic.

★ When this WOULD be the correct answer

This would be correct if the VM is in a subnet without an NSG (or with an allow-all rule) but the VM's NIC has no public IP, and you need to enable inbound RDP from the internet by assigning a public IP and adding an NSG rule on the NIC.

Why candidates choose this

Candidates may think a public IP directly on the VM bypasses subnet-level restrictions, misunderstanding that NSGs are independent of public IP assignment.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,053 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A VM in subnet S1 must accept RDP only from the administrator workstation at 203.0.113.25. The subnet NSG has a custom inbound deny-all rule at priority 200 and a custom allow-RDP rule at priority 300 for source 203.0.113.25, destination Any, TCP 3389. RDP is still blocked from the workstation. What should the administrator change?

medium
  • ✓ A.Move the allow-RDP rule to a lower priority number than 200.
  • B.Change the allow rule from inbound to outbound traffic.
  • C.Change the protocol from TCP to Any on the deny-all rule.
  • D.Attach a user-defined route so the workstation can reach the VM directly.

Why A: Network Security Group (NSG) rules are evaluated in priority order, with lower numbers having higher precedence. The deny-all rule at priority 200 is evaluated before the allow-RDP rule at priority 300, so the deny rule blocks the RDP traffic before the allow rule can be applied. To allow RDP from the workstation, the allow-RDP rule must have a lower priority number (e.g., 100) than the deny-all rule, ensuring it is evaluated first.

Variation 2. A subnet NSG contains these inbound rules: Priority 100 denies TCP 8443 from VirtualNetwork to any destination, Priority 110 allows TCP 8443 from AzureLoadBalancer to any destination, and Priority 200 allows TCP 8443 from ASG-Web to ASG-App. The app VM NIC has no additional inbound rules. Web servers are members of ASG-Web and the app VM is a member of ASG-App. The web tier still cannot connect to TCP 8443. What should the administrator change?

hard
  • ✓ A.Move the allow rule for ASG-Web to ASG-App to a priority lower than 100.
  • B.Replace ASG-Web with the VirtualNetwork service tag in the allow rule.
  • C.Add a route table that sends TCP 8443 traffic to the app subnet.
  • D.Create a second NSG on the app NIC with an allow rule at priority 50.

Why A: NSG rules are evaluated in priority order, from lowest to highest number. The deny rule at priority 100 explicitly blocks TCP 8443 from VirtualNetwork, which includes traffic from ASG-Web (since ASG-Web members are within the virtual network). The allow rule at priority 110 only permits traffic from AzureLoadBalancer, not from ASG-Web. The allow rule at priority 200 is never evaluated because the deny rule at priority 100 matches first. By moving the allow rule for ASG-Web to ASG-App to a priority lower than 100 (e.g., 90), it will be evaluated before the deny rule, allowing the web servers to connect.

Variation 3. A web tier and API tier run in different subnets. The API subnet NSG currently has Deny-8443 from Any at priority 200 and Allow-8443-WebToApi from ASG-Web to ASG-Api at priority 300. Web requests on TCP 8443 are failing. Which two changes should the administrator make? Select two.

medium
  • A.Move the allow rule to a higher priority number than 200.
  • ✓ B.Move the allow rule to a lower priority number than 200.
  • ✓ C.Ensure the web NICs are added to ASG-Web and the API NICs are added to ASG-Api.
  • D.Change the rule protocol from TCP to Any.
  • E.Attach a route table to the API subnet to override the deny behavior.

Why B: B is correct because NSG rules are evaluated in priority order, with lower numbers having higher priority. The Deny-8443 rule at priority 200 is evaluated before the Allow-8443-WebToApi rule at priority 300, so the deny rule blocks the traffic. Moving the allow rule to a lower priority number (e.g., 100) ensures it is evaluated first, allowing the traffic. C is correct because the allow rule uses application security groups (ASGs); if the web and API NICs are not assigned to the respective ASGs, the rule will not match any traffic, effectively making it a no-op.

Variation 4. A Linux VM in a subnet must accept SSH only from the corporate admin subnet 10.8.4.0/24. The subnet NSG currently has an Allow-SSH rule for Any at priority 300 and a Deny-SSH rule for Any at priority 200. Administrators from 10.8.4.0/24 still cannot connect. What change should the administrator make?

medium
  • A.Change the deny rule protocol from TCP to Any so the allow rule is evaluated first.
  • ✓ B.Add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200.
  • C.Move the existing Allow-SSH rule to priority 400 so it applies later.
  • D.Add a route table to the subnet so the SSH packets follow a different path.

Why B: In an NSG, rules are processed in priority order from lowest number to highest, and the first matching rule wins, so the Deny-SSH rule at priority 200 is evaluated before the Allow-SSH rule at priority 300 and blocks all SSH traffic including from 10.8.4.0/24. The correct fix is to add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200 (for example 100), so it is evaluated before the deny rule and permits the admin subnet. Option A does not help because changing the protocol to Any still leaves the deny rule at a lower priority number than the allow rule, so it still matches first. Option C makes the problem worse by moving the allow rule to priority 400, which is evaluated even later. Option D is irrelevant because NSG filtering, not routing, is what is blocking the SSH connection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.