Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

A company has two application tiers: web servers and application servers. They want to allow traffic from the web servers to the application servers on port 8080, but only for a specific set of web servers. They have deployed the web servers in an Availability Set and want to use a single NSG rule to allow traffic from any web server that is part of that application tier. Which component should they use?

⚠ Common exam trap

Watch out — candidates often confuse Application Security Groups with Network Security Groups themselves, or mistakenly think Service Tags can be used to group custom sets of VMs, when in fact Service Tags are only for Azure services or broad network scopes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application security group

An Application Security Group (ASG) allows you to group virtual machines logically by their application roles (e.g., web servers) and then use that ASG as the source in a single NSG rule. Since the web servers are in an Availability Set, you can assign the same ASG to their NICs, and the NSG rule will dynamically include all current and future VMs in that ASG. This meets the requirement to allow traffic from any web server in that tier to the application servers on port 8080 without maintaining individual IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application security group

    Why this is correct

    An application security group (ASG) is the correct choice because it lets you group VM network interfaces by workload role, such as all web servers, and reference that group directly as the source in a network security group (NSG) rule. As VMs are added or removed from the tier, the ASG membership updates automatically, so the NSG rule dynamically reflects the current set of web server IP addresses without requiring manual edits. ASGs provide a scalable, intent-based way to enforce microsegmentation and zero-trust network access across VMs.

  • ✗

    Service tag

    Why it's wrong here

    A service tag is incorrect because it represents a predefined set of IP address ranges belonging to a specific Azure service (for example, Storage.WestUS, AzureLoadBalancer, or VirtualNetwork), not a custom group of your own VMs. If you use a service tag as the source, the NSG rule would match traffic coming from those Azure service IPs, not specifically from your web server VMs. Service tags are useful for controlling access to Azure PaaS services, but they cannot model an application tier made of your own virtual machines.

  • ✗

    Source IP address range

    Why it's wrong here

    Using a source IP address range is incorrect because it would require you to enumerate every web server's individual CIDR block or IP address in the NSG rule. This approach is brittle and does not scale: whenever a web server is added, removed, or receives a new IP address, you must manually update the rule, and overlapping or fragmented ranges quickly become difficult to manage. The scenario calls for a logical grouping of web servers, which is exactly what an application security group provides rather than relying on static, physical address values.

  • ✗

    Virtual network peering

    Why it's wrong here

    Virtual network peering is incorrect because it is a connectivity construct that links two or more virtual networks so that resources in each VNet can communicate via private IP addresses; it is not a source that can be used in an NSG rule. NSG rules allow sources such as IP address ranges, service tags, or application security groups, but peering itself never appears as a source or destination. While VNet peering might be relevant to routing traffic between a web tier and an application tier in different VNets, it does not solve the problem of grouping your web server VMs for NSG rule matching.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.