AZ-500 Secure networking Practice Question
You are designing a network security strategy for a multi-tier application. The web tier must be accessible from the internet, but the application and database tiers must only be accessible from the web tier. Which Azure solution should you use to isolate the tiers?
⚠ Common exam trap
A common mix-up: candidates confuse centralized firewall solutions (like Azure Firewall) with subnet-level access control, forgetting that NSGs are the native, lightweight, and correct tool for per-subnet traffic filtering in a multi-tier architecture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network security groups (NSGs) on each subnet
Network security groups (NSGs) on each subnet are the correct solution because they provide stateful, layer-3/layer-4 traffic filtering at the subnet level. By placing the web tier in a subnet with an NSG that allows inbound HTTP/HTTPS from the internet, and placing the application and database tiers in separate subnets with NSGs that only allow inbound traffic from the web tier subnet (using source IP ranges or service tags), you effectively isolate the tiers while permitting the required east-west traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure DDoS Protection
Why it's wrong here
Azure DDoS Protection is a perimeter-focused mitigation service that detects and absorbs volumetric, protocol, and resource-layer attacks (e.g., SYN floods, UDP amplification) targeting your public IPs. While it protects availability, it does not inspect or filter normal north-south or east-west traffic between the application and database subnets, and it offers no L3/L4 rule engine to define allowed source/destination pairs. Therefore, it cannot create the network-level isolation required to separate tiers inside a VNet.
- ✗
Azure Firewall with application rules
Why it's wrong here
Azure Firewall with application rules primarily filters outbound HTTP/S traffic based on FQDNs or URLs, or inbound traffic to public IPs at Layer 7. This mechanism does not provide the required *network-level isolation* between private subnets for the application and database tiers, which typically relies on IP address and port-based access controls. It is tempting because it offers advanced application-layer security, and would be suitable for controlling outbound access to specific web services or for protecting the web tier from application-layer threats.
- ✓
Network security groups (NSGs) on each subnet
Why this is correct
Network security groups (NSGs) are stateful, L3/L4 filtering entities that can be associated to either a subnet or a NIC, making them an ideal tool to isolate tiers within a VNet. For example, you can create a rule on the database subnet that only allows inbound TCP 1433 from the application subnet's address prefix, while denying all other inbound traffic. NSGs provide the required network-level segmentation with no need for a separate gateway or virtual appliance, and they combine easily with service tags and application security groups for maintainability.
- ✗
Azure Private Link
Why it's wrong here
Azure Private Link lets you access an Azure service (such as SQL Database, Blob Storage, or your own service) through a private IP address inside your VNet, steering traffic along the Microsoft backbone instead of the public internet. However, it is a service-to-client connectivity feature, not a policy engine: once the endpoint is deployed, it does not evaluate which subnets or IP addresses can talk to each other, and it has no concept of allow/deny rules between your application and database tier. It cannot enforce east-west segmentation; you still need NSGs or other controls to restrict traffic between the tiers.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.