Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

You are designing a network security solution for a multi-tier application in Azure. The web tier must be accessible from the internet, the application tier only from the web tier, and the database tier only from the application tier. All tiers are in different subnets of the same VNet. What is the minimum configuration?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing Azure Firewall or separate VNets, forgetting that NSGs on subnets within a single VNet provide the simplest and most cost-effective way to enforce tier-to-tier access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure NSGs on each subnet with appropriate allow rules.

Network Security Groups (NSGs) applied to each subnet can enforce least-privilege network access: allow inbound from Internet to the web tier subnet, allow inbound only from the web tier subnet to the application tier subnet, and allow inbound only from the application tier subnet to the database tier subnet. This is the minimum configuration as it uses built-in, no-cost Azure constructs without additional services or complex routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use service endpoints for each tier.

    Why it's wrong here

    Service endpoints are designed to secure outbound access from a subnet to specific Azure PaaS services by binding the subnet's identity, but they do not provide any mechanism to filter traffic between subnets within the same VNet. Even if you enabled service endpoints on each tier's subnet, traffic from the web tier to the app tier would still be allowed by default, because service endpoints do not inspect packets or enforce rules based on ports or protocols. The only way to isolate tiers is to apply traffic filtering rules, which service endpoints cannot do. Therefore, this option entirely fails to address the requirement for network isolation between subnets.

  • ✗

    Create separate VNets for each tier and use VNet peering.

    Why it's wrong here

    Creating separate VNets and using peering fails here because the question explicitly states all tiers reside in different subnets of the *same* VNet. This option fundamentally contradicts that design constraint, as VNet peering connects distinct virtual networks, not subnets within a single VNet. It is tempting because peering is the correct solution for securely connecting applications or services distributed across multiple, isolated virtual networks, particularly when strong administrative or subscription separation is required.

  • ✗

    Deploy Azure Firewall in the VNet and route all traffic through it.

    Why it's wrong here

    Azure Firewall is a managed, stateful firewall that can inspect and filter inter-subnet traffic, but deploying it here would require adding a dedicated firewall subnet, creating user-defined routes to force all traffic through the firewall's private IP, and paying hourly and data-processing fees for every packet. This approach is significantly overengineered and costly for the simple task of isolating three tiers within a single VNet, where NSGs can enforce the same allowed flows at no charge and with no routing changes. Azure Firewall is better suited for perimeter security, internet-bound traffic inspection, or centralized logging and should complement NSGs rather than replace them. Thus, it is a valid but impractical solution for this requirement.

  • ✓

    Configure NSGs on each subnet with appropriate allow rules.

    Why this is correct

    Network Security Groups are the native Azure mechanism for filtering traffic between subnets, as they contain stateful rules that allow or deny traffic based on source and destination IP, port, and protocol. By assigning a distinct NSG to the web, app, and data subnets, you can explicitly permit only the necessary flows—for instance, web tier to app tier on port 443, and app tier to data tier on port 1433—while blocking all other traffic by default. NSGs are applied directly to subnets or NICs, incur no additional cost, and require no custom routing, making them the most efficient and cost-effective solution for east-west traffic isolation within a VNet. This aligns with Azure's defense-in-depth guidance of securing every subnet with an NSG.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.