Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

You are a security engineer at Contoso. The company has an Azure virtual network named VNet1 with a subnet named WebSubnet that hosts internet-facing Linux VMs. You need to restrict inbound traffic to WebSubnet so that only HTTP (TCP 80) and HTTPS (TCP 443) from the internet are allowed, and all other inbound traffic is denied. The VMs must remain reachable over SSH from a jump host in another subnet for management. What should you configure?

⚠ Common exam trap

The trap here is assuming that a user-defined route or Azure Firewall DNAT can replace an NSG for restricting inbound ports to a subnet, when only an NSG provides stateful, subnet-level inbound filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a network security group (NSG) and associate it with WebSubnet. Add inbound rules allowing TCP 80 and 443 from source Internet, allowing TCP 22 from the jump host subnet, and a final rule denying all other inbound traffic with a higher priority number.

A network security group attached to WebSubnet enforces inbound rules at the subnet boundary. Allowing TCP 80 and 443 from Internet, allowing TCP 22 from the jump host subnet, and placing a deny-all rule at a higher priority number blocks all other inbound traffic. This satisfies both the internet restriction and the management requirement without extra routing changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a network security group (NSG) and associate it with WebSubnet. Add inbound rules allowing TCP 80 and 443 from source Internet, allowing TCP 22 from the jump host subnet, and a final rule denying all other inbound traffic with a higher priority number.

    Why this is correct

    This is correct because an NSG applied to WebSubnet filters traffic at the subnet level. Rules are processed by priority, lowest number first. Allowing 80/443 from Internet, allowing 22 from the jump host subnet, and adding a low-priority deny-all rule enforces the required restriction while preserving management access from the jump host.

  • ✗

    Create a user-defined route (UDR) on WebSubnet that sends all traffic to a virtual network gateway, and configure the gateway to allow only TCP 80 and 443.

    Why it's wrong here

    A UDR controls outbound routing from the subnet, not inbound filtering. A virtual network gateway routes traffic between networks; it does not act as a stateful firewall that can permit or deny specific inbound ports, so this approach would not enforce the required restrictions.

  • ✗

    Configure a service endpoint for Microsoft.Storage on WebSubnet and create a storage account firewall rule that allows only HTTP and HTTPS.

    Why it's wrong here

    Service endpoints are for optimizing and securing access to Azure PaaS services, not for controlling inbound internet traffic to VMs. A storage account firewall rule applies to the storage account, not to WebSubnet, so it cannot restrict inbound connections to the web VMs.

  • ✗

    Create an Azure Firewall in a GatewaySubnet and configure DNAT rules to forward TCP 80 and 443 to the web VMs, and network rules to deny all other inbound traffic.

    Why it's wrong here

    Azure Firewall DNAT is used for publishing services, but it does not restrict traffic already destined to the VMs' private IPs. Without a route table forcing traffic through the firewall, inbound traffic can still reach the VMs directly, so this does not enforce the required subnet-level restriction.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.