Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

Understanding NSG Rule Priority: Allow vs Deny

Exhibit

Inbound NSG rules on the app subnet:
Priority 100  Deny   TCP 8443  Source: VirtualNetwork   Destination: Any
Priority 110  Allow  TCP 8443  Source: AzureLoadBalancer Destination: Any
Priority 200  Deny   Any       Source: Any              Destination: Any

The web tier and app tier are in the same virtual network. The app tier uses application security group ASG-App. The web tier uses application security group ASG-Web.

Based on the exhibit, why is TCP 8443 traffic from the web tier still denied to the app tier, and what should you do to allow only the web tier?

Quick Answer

The correct answer is to add an inbound allow rule for TCP 8443 from ASG-Web to ASG-App with a priority lower than 100. This is because Azure NSG rule priority order is evaluated from lowest number to highest, so a deny-all rule at priority 200 will block all traffic that hasn’t been explicitly allowed by a rule with a lower number. The existing allow rule at priority 100 permits traffic from the web tier, but it does not specifically cover TCP 8443, leaving that port subject to the subsequent deny-all rule. On the AZ-104 exam, this scenario tests your understanding of how NSG rule priority order determines whether an allow or deny rule takes effect—a common trap is assuming a general allow rule covers all ports, when in fact a lower-priority deny rule can override it if the specific port isn’t explicitly allowed. To fix this, you must insert a new allow rule for TCP 8443 with a priority between 100 and 200, ensuring it is evaluated before the deny-all rule. Memory tip: think of NSG priority like a bouncer checking IDs—lower numbers get in first, and a “deny all” at the back of the line only stops those without a specific pass.

⚠ Common exam trap

Many candidates assume changing the deny-all rule is the simplest fix, but they overlook that it would open the port to all sources, not just the web tier, failing the specific requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add an inbound allow rule for TCP 8443 from ASG-Web to ASG-App with a priority lower than 100.

In Azure Network Security Groups (NSGs), rules are evaluated in priority order, with lower numbers evaluated first. The existing rule at priority 100 allows traffic from the web tier but does not explicitly allow TCP 8443, so a subsequent deny-all rule at priority 200 blocks it. To allow only the web tier, you must add an inbound allow rule for TCP 8443 from ASG-Web with a priority lower than 100 (e.g., 90). This new rule is evaluated before the existing rule at priority 100, permitting the desired traffic while still blocking other sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Change the deny-all rule at priority 200 to allow TCP 8443 from ASG-Web.

    Why it's wrong here

    That rule is lower priority and never gets evaluated for this traffic because an earlier deny already matches.

    When this WOULD be correct

    If the question required allowing TCP 8443 traffic from any source to the app tier, and the only blocking rule was the deny-all at priority 200, then modifying that rule to allow the traffic would be correct.

  • Add an inbound allow rule for TCP 8443 from ASG-Web to ASG-App with a priority lower than 100.

    Why this is correct

    An allow rule must be evaluated before the existing deny rule, and using ASGs limits access to the web tier.

  • Add a route table entry for 8443 traffic from the web tier to the app tier.

    Why it's wrong here

    Routes determine next hop selection, not whether NSG rules allow or deny a port.

    When this WOULD be correct

    If the question described that traffic between subnets was being incorrectly routed (e.g., via a misconfigured virtual appliance or missing route), then adding a route table entry to direct TCP 8443 traffic from the web subnet to the app subnet would be the correct action.

  • Remove the AzureLoadBalancer rule because it is overriding the web tier traffic.

    Why it's wrong here

    The AzureLoadBalancer rule only affects probe traffic and does not block web tier connections.

    When this WOULD be correct

    This option would be correct if the AzureLoadBalancer rule had a higher priority and was explicitly blocking TCP 8443 from the web tier, and removing it would allow the traffic while still maintaining security.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Add an inbound allow rule for TCP 8443 from ASG-Web to ASG-App with a priority lower than 100.Correct answer

Why this is correct

An allow rule must be evaluated before the existing deny rule, and using ASGs limits access to the web tier.

Change the deny-all rule at priority 200 to allow TCP 8443 from ASG-Web.Wrong answer — click to see why

Why this is wrong here

Changing the deny-all rule at priority 200 to allow TCP 8443 would allow traffic from all sources, not just the web tier, violating the requirement to restrict access to ASG-Web only.

★ When this WOULD be the correct answer

If the question required allowing TCP 8443 traffic from any source to the app tier, and the only blocking rule was the deny-all at priority 200, then modifying that rule to allow the traffic would be correct.

Why candidates choose this

Candidates may think modifying the explicit deny rule is the simplest fix, overlooking that it would open access broadly instead of restricting to the web tier.

Add a route table entry for 8443 traffic from the web tier to the app tier.Wrong answer — click to see why

Why this is wrong here

Route tables control traffic routing between subnets, not firewall rules. The question involves Network Security Group (NSG) rules, which filter traffic at the subnet or NIC level; adding a route table entry does not affect NSG allow/deny decisions.

★ When this WOULD be the correct answer

If the question described that traffic between subnets was being incorrectly routed (e.g., via a misconfigured virtual appliance or missing route), then adding a route table entry to direct TCP 8443 traffic from the web subnet to the app subnet would be the correct action.

Why candidates choose this

Candidates may confuse the function of route tables (which direct traffic paths) with NSGs (which filter traffic), especially when troubleshooting connectivity issues, leading them to think a routing change can override a security rule.

Remove the AzureLoadBalancer rule because it is overriding the web tier traffic.Wrong answer — click to see why

Why this is wrong here

Removing the AzureLoadBalancer rule would not fix the issue because that rule is likely needed for Azure Load Balancer health probes, and it does not override web tier traffic; the deny-all rule at priority 200 is blocking the traffic.

★ When this WOULD be the correct answer

This option would be correct if the AzureLoadBalancer rule had a higher priority and was explicitly blocking TCP 8443 from the web tier, and removing it would allow the traffic while still maintaining security.

Why candidates choose this

Candidates may think the AzureLoadBalancer rule is interfering because it appears as a default rule, and they might assume removing it will allow traffic without understanding its purpose for health probes.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

5 more ways this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A subnet NSG contains these inbound rules: Priority 100 denies TCP 8443 from VirtualNetwork to any destination, Priority 110 allows TCP 8443 from AzureLoadBalancer to any destination, and Priority 200 allows TCP 8443 from ASG-Web to ASG-App. The app VM NIC has no additional inbound rules. Web servers are members of ASG-Web and the app VM is a member of ASG-App. The web tier still cannot connect to TCP 8443. What should the administrator change?

hard
  • A.Move the allow rule for ASG-Web to ASG-App to a priority lower than 100.
  • B.Replace ASG-Web with the VirtualNetwork service tag in the allow rule.
  • C.Add a route table that sends TCP 8443 traffic to the app subnet.
  • D.Create a second NSG on the app NIC with an allow rule at priority 50.

Why A: NSG rules are evaluated in priority order, from lowest to highest number. The deny rule at priority 100 explicitly blocks TCP 8443 from VirtualNetwork, which includes traffic from ASG-Web (since ASG-Web members are within the virtual network). The allow rule at priority 110 only permits traffic from AzureLoadBalancer, not from ASG-Web. The allow rule at priority 200 is never evaluated because the deny rule at priority 100 matches first. By moving the allow rule for ASG-Web to ASG-App to a priority lower than 100 (e.g., 90), it will be evaluated before the deny rule, allowing the web servers to connect.

Variation 2. A web tier and API tier run in different subnets. The API subnet NSG currently has Deny-8443 from Any at priority 200 and Allow-8443-WebToApi from ASG-Web to ASG-Api at priority 300. Web requests on TCP 8443 are failing. Which two changes should the administrator make? Select two.

medium
  • A.Move the allow rule to a higher priority number than 200.
  • B.Move the allow rule to a lower priority number than 200.
  • C.Ensure the web NICs are added to ASG-Web and the API NICs are added to ASG-Api.
  • D.Change the rule protocol from TCP to Any.
  • E.Attach a route table to the API subnet to override the deny behavior.

Why B: B is correct because NSG rules are evaluated in priority order, with lower numbers having higher priority. The Deny-8443 rule at priority 200 is evaluated before the Allow-8443-WebToApi rule at priority 300, so the deny rule blocks the traffic. Moving the allow rule to a lower priority number (e.g., 100) ensures it is evaluated first, allowing the traffic. C is correct because the allow rule uses application security groups (ASGs); if the web and API NICs are not assigned to the respective ASGs, the rule will not match any traffic, effectively making it a no-op.

Variation 3. A Linux VM in a subnet must accept SSH only from the corporate admin subnet 10.8.4.0/24. The subnet NSG currently has an Allow-SSH rule for Any at priority 300 and a Deny-SSH rule for Any at priority 200. Administrators from 10.8.4.0/24 still cannot connect. What change should the administrator make?

medium
  • A.Change the deny rule protocol from TCP to Any so the allow rule is evaluated first.
  • B.Add an Allow-SSH rule for 10.8.4.0/24 with a priority lower than 200.
  • C.Move the existing Allow-SSH rule to priority 400 so it applies later.
  • D.Add a route table to the subnet so the SSH packets follow a different path.

Why B: The subnet NSG has a Deny-SSH rule for Any at priority 200, which blocks all SSH traffic regardless of source. To allow SSH only from 10.8.4.0/24, an Allow-SSH rule for that specific subnet must be added with a priority lower (numerically smaller) than 200, such as 150, so it is evaluated before the deny rule. Since NSG rules are processed in ascending priority order (lowest number first), the allow rule at a lower number will match traffic from 10.8.4.0/24 and permit it, preventing the deny rule from being evaluated for that source. Option B correctly describes adding an allow rule with priority lower than 200.

Variation 4. A VM in subnet S1 must accept RDP only from the administrator workstation at 203.0.113.25. The subnet NSG has a custom inbound deny-all rule at priority 200 and a custom allow-RDP rule at priority 300 for source 203.0.113.25, destination Any, TCP 3389. RDP is still blocked from the workstation. What should the administrator change?

medium
  • A.Move the allow-RDP rule to a lower priority number than 200.
  • B.Change the allow rule from inbound to outbound traffic.
  • C.Change the protocol from TCP to Any on the deny-all rule.
  • D.Attach a user-defined route so the workstation can reach the VM directly.

Why A: Network Security Group (NSG) rules are evaluated in priority order, with lower numbers having higher precedence. The deny-all rule at priority 200 is evaluated before the allow-RDP rule at priority 300, so the deny rule blocks the RDP traffic before the allow rule can be applied. To allow RDP from the workstation, the allow-RDP rule must have a lower priority number (e.g., 100) than the deny-all rule, ensuring it is evaluated first.

Variation 5. A VM in Azure cannot accept RDP connections from your office public IP. The subnet NSG already has an inbound deny-all rule at priority 200, and you added an allow rule for TCP 3389 from 198.51.100.25/32 at priority 300. What should you do to allow the connection?

medium
  • A.Change the source to Internet so the allow rule matches more traffic.
  • B.Create or move the allow rule to priority 100 so it is evaluated before the deny rule.
  • C.Change the protocol from TCP to Any to bypass the deny rule.
  • D.Assign a public IP directly to the VM to override the subnet NSG behavior.

Why B: Network Security Group (NSG) rules are evaluated in priority order, with lower numbers having higher precedence. Since the deny-all rule at priority 200 is evaluated before the allow rule at priority 300, the deny rule blocks the RDP traffic. To allow the connection, the allow rule must be created or moved to a priority lower than 200 (e.g., 100) so it is evaluated first, permitting traffic from 198.51.100.25/32 on TCP 3389 before the deny rule is reached.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.