Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

Exhibit

Get-AzNetworkSecurityGroup -Name 'WebNSG' -ResourceGroupName 'ProdRG' | Get-AzNetworkSecurityRuleConfig -Name 'AllowSSH' | Format-List

Refer to the exhibit. You run the PowerShell command above and get the output: Access: Allow, SourceAddressPrefix: *, DestinationAddressPrefix: VirtualNetwork, DestinationPortRange: 22, Protocol: TCP, Priority: 100. A security audit requires that SSH access be restricted to only the management subnet (10.0.1.0/24). What should you do?

⚠ Common exam trap

Many candidates confuse SourceAddressPrefix and DestinationAddressPrefix, mistakenly thinking that changing the destination restricts the source, or they overcomplicate the solution by adding a deny rule instead of simply modifying the existing rule's source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the SourceAddressPrefix to '10.0.1.0/24'.

The existing rule allows SSH (TCP port 22) from any source (*) to the virtual network. To restrict SSH access to only the management subnet (10.0.1.0/24), you must change the SourceAddressPrefix from '*' to '10.0.1.0/24'. This ensures only traffic originating from the management subnet is permitted, meeting the security audit requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Change the SourceAddressPrefix to '10.0.1.0/24'.

    Why this is correct

    Changing SourceAddressPrefix to '10.0.1.0/24' correctly scopes the inbound SSH rule so that only clients from the management subnet can initiate connections to port 22. In an NSG rule, the source address prefix explicitly controls the allowable origin of traffic, and this change restricts the rule to the intended administrative range. This is the minimal and proper modification to enforce the stated network security requirement.

  • ✗

    Change the DestinationAddressPrefix to '10.0.1.0/24'.

    Why it's wrong here

    The DestinationAddressPrefix determines the endpoint of the traffic, not the origin, so setting it to '10.0.1.0/24' would match packets destined for the management subnet while leaving the source as 'Any'. This would not restrict SSH clients to the management subnet; rather, it could allow any source to reach SSH on the management subnet, which is the opposite of the intent. The source prefix must be modified instead.

  • ✗

    Change the Access to Deny and create a new rule to allow SSH from management subnet.

    Why it's wrong here

    Changing the existing rule to 'Deny' and then adding a separate allow rule for the management subnet introduces unnecessary complexity and a risk of priority misordering. Because NSG rules are processed in numeric priority order, if the deny rule has a lower numeric priority (evaluated first) than the new allow rule, all SSH traffic will be blocked, including from management. The straightforward, reliable fix is to simply restrict the source of the existing rule to 10.0.1.0/24, avoiding the need for multiple rules.

  • ✗

    Change the SourceAddressPrefix to 'VirtualNetwork'.

    Why it's wrong here

    The 'VirtualNetwork' service tag matches all traffic originating from any address space within the virtual network, including subnets other than the management subnet. This broadens the source scope beyond the intended 10.0.1.0/24, potentially allowing other workloads to use SSH. A specific IP prefix is necessary to limit access to the management subnet only.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.