AZ-500 Secure compute, storage, and databases Practice Question
You are deploying a three-tier application on Azure VMs. The web tier must be accessible from the internet, but the application and database tiers must only accept traffic from the web tier. You need to implement network segmentation using Azure networking components. What is the most secure and manageable solution?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing Azure Firewall or VNet peering, not realizing that NSGs on separate subnets within the same VNet are the simplest, most cost-effective, and most secure way to enforce east-west traffic restrictions between application tiers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use separate subnets for each tier in the same VNet and configure NSGs to allow traffic only from the previous tier.
Placing each tier in its own subnet within the same VNet allows you to apply Network Security Groups (NSGs) at the subnet level with inbound rules that restrict traffic to only the previous tier's subnet IP range. This follows the principle of least privilege and provides a clear, manageable boundary between tiers without introducing unnecessary complexity or performance overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a single subnet and configure NSGs on VM NICs to restrict traffic.
Why it's wrong here
Using a single subnet means all VMs in every tier share the same subnet boundary, so there is no network-level isolation between web, application, and database tiers. While NSGs attached to each VM's NIC can filter traffic, this approach requires duplicating rules on every individual NIC, and if a new VM is added to a tier, its NIC must be manually associated with the correct NSG. It also prevents you from applying a single, consistent default policy per tier, and it is far more error-prone than applying NSGs at the subnet level.
- ✗
Use VNet peering to connect separate VNets for each tier and use NSGs.
Why it's wrong here
VNet peering is designed to connect separate virtual networks, not to segment tiers inside a single application perimeter. Adopting a separate VNet per tier means you must configure bidirectional peering, potentially deal with overlapping address spaces, and manage distinct route tables and NSGs across multiple VNets, all while gaining no additional security isolation over subnets in the same VNet. This adds administrative overhead, can increase cross-VNet latency and egress costs, and is not the recommended architecture for a simple three-tier app on Azure VMs.
- ✗
Use a single VNet with one subnet and use Azure Firewall to filter traffic between tiers.
Why it's wrong here
Placing all tiers in a single subnet and relying on Azure Firewall to mediate inter-tier traffic still leaves every VM in the same broadcast domain, so the firewall must be inserted as a forced next hop (UDR) to intercept traffic that Azure otherwise routes directly. Azure Firewall is a stateful, managed service with substantial hourly cost and a dedicated subnet requirement, making it heavy overkill for simple tier-to-tier filtering. Additionally, without separate subnets you cannot apply NSG-based access control per tier, and all traffic, including unintended east-west flows, is forced through the firewall, increasing complexity and operational expense.
- ✓
Use separate subnets for each tier in the same VNet and configure NSGs to allow traffic only from the previous tier.
Why this is correct
Segmenting the VNet into separate subnets for each tier is the core of Azure network security for app workloads, because it lets you attach an NSG at the subnet boundary and enforce least-privilege traffic flow. For example, you can create a rule that allows only the application subnet to access the database subnet on TCP 1433, and only the web subnet to access the application subnet on TCP 443, while the default deny-all rule blocks everything else. Because NSGs are stateful, rules apply to both directions and new VMs added to a subnet automatically inherit the same security posture, providing a scalable, manageable tier-isolation pattern.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.