You manage an Azure virtual network named VNet-App that contains a subnet named Subnet-Web with 40 web server VMs. The VMs must be reachable on TCP 443 from the internet, and Microsoft publishes service tags such as Internet, VirtualNetwork, and AzureLoadBalancer. You attach a network security group (NSG) named NSG-Web to Subnet-Web. You need to allow inbound HTTPS to the VMs while blocking all other inbound internet traffic. What should you configure in NSG-Web?
This is correct because an NSG rule with source service tag Internet, destination TCP 443, and Allow permits exactly the required HTTPS traffic. Azure NSGs have default rules that deny inbound traffic not explicitly allowed, so explicitly allowing 443 and relying on the built-in deny for everything else satisfies the requirement without needing to create a custom deny rule.
Why this answer
NSGs evaluate inbound rules by priority, and Azure provides default rules that deny inbound traffic from the internet unless a higher-priority allow rule matches. Creating an allow rule for the Internet service tag on TCP 443 permits only HTTPS, while the built-in default deny blocks everything else. Using VirtualNetwork or AzureLoadBalancer as the source would not match public client traffic, and allowing all ports would be overly permissive.
Exam trap
The trap here is assuming that a custom deny rule is required for all other traffic, when Azure NSGs already include default inbound deny rules that handle this automatically.