AZ-500 Secure networking Practice Question
Which TWO actions should you take to secure a virtual network in Azure? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse Azure Bastion (a PaaS management service) with a network security control, or think Azure Monitor alerts can actively block traffic, when in fact neither provides traffic filtering or perimeter security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply network security groups (NSGs) to subnets.
Network security groups (NSGs) are a fundamental Azure security control that filter traffic at the subnet or network interface level. Applying an NSG to a subnet allows you to define inbound and outbound security rules based on source/destination IP, port, and protocol, effectively segmenting and protecting the virtual network from unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply network security groups (NSGs) to subnets.
Why this is correct
Network security groups (NSGs) are a core, stateful filtering layer in Azure that enforce allow/deny rules based on source/destination IP, port, and protocol. When applied to subnets, they segment traffic between workloads inside a VNet and control traffic entering or leaving the subnet from the internet or peered networks. NSGs also provide default rules and support service tags, making them a fundamental security action for any VNet.
- ✗
Configure Azure DNS zones.
Why it's wrong here
Azure DNS zones are a name resolution service, either public or private, that hosts DNS records such as A, CNAME, or MX for domains. They translate human-readable names to IP addresses but do not inspect or filter network packets, block unauthorized connections, or enforce security policies. Configuring DNS zones neither strengthens the VNet's perimeter nor protects resources from network-level threats, so it is not a valid action for securing a virtual network.
- ✗
Deploy Azure Bastion for VM access.
Why it's wrong here
Azure Bastion is a managed PaaS service that provides secure, browser-based RDP/SSH access to VMs through TLS, eliminating the need for public IP addresses on those VMs. While it protects the management plane from direct internet exposure, it does not filter traffic between subnets, control inbound/outbound connectivity for applications, or enforce network-level security policies. Bastion addresses only the access path to VMs, not the overall security of the VNet itself.
- ✓
Implement Azure Firewall for perimeter control.
Why this is correct
Azure Firewall is a stateful, managed firewall service that provides centralized inbound and outbound traffic filtering at the perimeter of a VNet. It supports application rules (FQDN-based), network rules, threat intelligence, and SNAT/DNAT, enabling granular control over traffic between the VNet and external networks. Deploying Azure Firewall in a hub VNet is a best practice for protecting spoke VNets and complements NSGs by adding advanced, centralized perimeter security.
- ✗
Set up Azure Monitor alerts.
Why it's wrong here
Azure Monitor alerts are a monitoring capability that sends notifications when conditions such as metric thresholds, log queries, or activity events are met. Alerts help detect potential security issues and trigger responses, but they take no direct action to block, filter, or isolate network traffic. Merely setting up alerts does not secure the VNet; security requires enforcement mechanisms like NSGs and Azure Firewall, not just visibility or notification.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.