AZ-500 Secure networking Practice Question
You are designing network security for a multi-tier application. The web tier must be accessible from the internet, but the database tier must only be accessible from the web tier. Both tiers are in the same virtual network. Which Azure service should you use to restrict traffic between the tiers?
⚠ Common exam trap
AZ-500 often tests the difference between NSGs and ASGs; candidates might pick ASGs thinking they restrict traffic, but ASGs are just grouping mechanisms that must be used with NSGs to define rules. The key is that NSGs are the actual enforcement point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network Security Group (NSG)
Network Security Groups (NSGs) are used to filter network traffic to and from Azure resources within a virtual network. They contain security rules that allow or deny inbound and outbound traffic based on source/destination IP, port, and protocol. By applying NSGs to the subnets or NICs of the web and database tiers, you can restrict database access to only the web tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Route table
Why it's wrong here
Route tables (UDRs) affect the path that packets take by overriding Azure's default system routes, but they cannot inspect or permit/deny traffic by port, protocol, or application. Associating a route table with a subnet only changes next-hop behavior (e.g., sending traffic to a virtual appliance or forcing tunnel), so it lacks the rule-based allow/deny constructs needed for tier-to-tier access control.
- ✓
Network Security Group (NSG)
Why this is correct
Network Security Groups (NSGs) are the correct native solution because they filter traffic between subnets and NICs using priority-ordered security rules based on source/destination IP, port, and protocol. NSGs are stateful, meaning a permitted inbound flow's return traffic is automatically allowed, and they can be associated directly with the database subnet to only permit port 1433 from the app tier's subnet/IPs.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, stateful, centralized network/application firewall (with FQDN filtering and threat intelligence), but it is an overlay service that requires a route table to direct traffic to it. For a simple multi-tier app requiring only subnet-to-subnet port filtering, deploying Azure Firewall adds licensing cost, hub infrastructure, and complexity when a subnet-associated NSG can achieve the same control.
- ✗
Application Security Groups (ASGs)
Why it's wrong here
Application Security Groups (ASGs) allow you to group VMs by application role in the NSG rule's source or destination, simplifying rule management through names like 'WebServers' instead of individual IPs. However, an ASG alone is only a logical object; it does not enforce any filtering by itself — the NSG rule must reference the ASG, and in this scenario the primary control is still an NSG.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.