AZ-500 Secure networking Practice Question
Exhibit
{
"name": "AllowSSHOnly",
"properties": {
"protocol": "Tcp",
"sourcePortRange": "*",
"destinationPortRange": "22",
"sourceAddressPrefix": "10.0.0.0/24",
"destinationAddressPrefix": "10.0.1.0/24",
"access": "Allow",
"priority": 100,
"direction": "Inbound"
}
}Refer to the exhibit. You are reviewing an NSG rule configuration for a subnet. The source subnet is 10.0.0.0/24 and the destination subnet is 10.0.1.0/24. What is the effect of this rule?
⚠ Common exam trap
Watch out — candidates often confuse the direction of the rule (inbound vs. outbound) or misinterpret the source and destination, leading them to think the rule blocks traffic or applies to the opposite direction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allows inbound SSH traffic from 10.0.0.0/24 to 10.0.1.0/24.
The rule shown in the exhibit is an inbound security rule with source 10.0.0.0/24, destination 10.0.1.0/24, protocol TCP, destination port 22 (SSH), and action Allow. This explicitly permits inbound SSH traffic from the source subnet to the destination subnet. Therefore, option D is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allows outbound SSH traffic from 10.0.1.0/24 to 10.0.0.0/24.
Why it's wrong here
This rule's direction is Inbound, so it is evaluated only for traffic entering the Azure network interface or subnet from the source prefix. The proposed statement describes an outbound flow, which would instead be matched against an outbound NSG rule with the source and destination reversed. Because this rule's action is Allow on an Inbound rule, it cannot permit or govern outbound SSH from 10.0.1.0/24 to 10.0.0.0/24.
- ✗
Blocks inbound SSH traffic from 10.0.0.0/24 to 10.0.1.0/24.
Why it's wrong here
The access value for this rule is 'Allow', not 'Deny', so it explicitly permits TCP port 22 traffic rather than rejecting it. An NSG rule prevents traffic only when the action is Deny; Allow rules are processed by priority and, if matched, the traffic is permitted before any lower-priority deny rule can be considered. Therefore the statement that it blocks inbound SSH is factually backwards—the rule is a positive permit for SSH from the specified source to destination.
- ✗
Allows all inbound traffic from 10.0.0.0/24 to 10.0.1.0/24.
Why it's wrong here
The rule's protocol is restricted to TCP and its destination port is set to 22 (SSH), so it does not apply to UDP, ICMP, or any other TCP port. To allow all inbound traffic, the protocol would need to be set to '*' and the destination port range to '*', which this configuration does not do. Thus, while the rule does allow inbound SSH, it is incorrect to characterize it as allowing all inbound traffic from 10.0.0.0/24 to 10.0.1.0/24.
- ✓
Allows inbound SSH traffic from 10.0.0.0/24 to 10.0.1.0/24.
Why this is correct
This rule is configured with Direction=Inbound, Source=10.0.0.0/24, Destination=10.0.1.0/24, Protocol=TCP, Destination Port=22, and Action=Allow. Those attributes match an inbound SSH connection from a host in the source subnet to any host in the destination subnet on port 22. Because the rule's priority places it ahead of the default deny rules and the traffic matches every condition, the rule allows that SSH traffic.
Visual reference
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.