Courseiva
Secure networking →easyMultiple Choice

AZ-500 Secure networking Practice Question

Exhibit

{
  "properties": {
    "addressSpace": {
      "addressPrefixes": ["10.0.0.0/16"]
    },
    "subnets": [
      {
        "name": "subnetA",
        "properties": {
          "addressPrefix": "10.0.1.0/24",
          "networkSecurityGroup": {
            "id": "/subscriptions/.../nsgA"
          }
        }
      },
      {
        "name": "subnetB",
        "properties": {
          "addressPrefix": "10.0.2.0/24",
          "networkSecurityGroup": {
            "id": "/subscriptions/.../nsgB"
          }
        }
      }
    ]
  }
}

Refer to the exhibit. You have a VNet with two subnets, each with a different NSG. Both NSGs have default rules. What is the default connectivity between VMs in subnetA and subnetB?

⚠ Common exam trap

A common mix-up: candidates assume separate NSGs on different subnets automatically block traffic between them, forgetting that the default 'AllowVNetInBound' rule overrides any implicit blocking and permits all intra-VNet communication unless explicitly denied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic is allowed by default.

By default, Network Security Groups (NSGs) include an inbound rule named 'AllowVNetInBound' that permits traffic from any virtual network (including peered VNets) to any destination within the VNet. Since subnetA and subnetB are both part of the same VNet, this default rule allows all traffic between VMs in these subnets, regardless of the separate NSG assignments. No additional configuration like peering is required because the subnets share the same virtual network boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Traffic is blocked by default.

    Why it's wrong here

    This statement is incorrect because Azure's default NSG rule set includes AllowVnetInBound and AllowVnetOutBound. These rules explicitly permit inbound and outbound traffic to and from the virtual network address space, which encompasses all subnets. Therefore, absent any custom deny rules, traffic between subnets in the same VNet is allowed, not blocked. A default deny would only appear if you explicitly create a rule with a higher priority.

  • ✗

    Traffic is allowed only if the VNet has peering.

    Why it's wrong here

    This statement is incorrect because virtual network peering is a mechanism to connect distinct virtual networks, not to enable communication within a single VNet. All subnets within a VNet share the same address space and routing path, and the default NSG rules already allow traffic between them. Peering is only necessary when traffic must cross the boundary between two separate VNets. Since the exhibit shows only one VNet, peering is irrelevant for subnet-to-subnet connectivity.

  • ✓

    Traffic is allowed by default.

    Why this is correct

    This statement is correct. When an NSG is associated with a subnet or NIC, Azure automatically applies default security rules; the relevant default inbound rule, AllowVnetInBound, permits any traffic from the VirtualNetwork source and destination. This rule covers all subnets in the same VNet, so intra-VNet traffic is allowed by default. To block such traffic, you must add a custom deny rule with a higher priority than the default allow rule.

  • ✗

    Traffic is allowed only if the subnets are in the same region.

    Why it's wrong here

    This statement is incorrect because the region does not influence NSG default rule behavior; the default rules use the virtualNetwork service tag to permit traffic within the VNet's defined address space. In Azure, a VNet exists within a single region, so all subnets in a VNet are automatically in the same region—but that is a property of the VNet, not a condition for the default allow. If subnets were in different regions, they would belong to different VNets and would require peering or another connection, yet the default NSG rules would still allow traffic within each VNet independently.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.