Courseiva
Secure networking →mediumMultiple Select

AZ-500 Secure networking Practice Question

You are designing network security for a three-tier application. You need to isolate each tier (web, application, data) and control traffic between them. Which TWO Azure services should you use to achieve this? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates choose Azure Firewall for all traffic control scenarios, overlooking that NSGs and ASGs are the native, lightweight solution for east-west traffic isolation within a single VNet, while Azure Firewall is designed for centralized, cross-VNet, and outbound traffic inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network Security Groups (NSGs)

Network Security Groups (NSGs) are correct because they let you define inbound and outbound security rules (by IP, port, and protocol) that filter traffic to and from subnets or NICs, which is exactly how you enforce isolation and control traffic between the web, application, and data tiers. Application Security Groups (ASGs) are correct because they let you group VMs by workload role (for example, web, app, or data) and then reference those groups as sources/destinations in NSG rules, so you can control tier-to-tier traffic without hardcoding individual IP addresses. Together, NSGs provide the filtering mechanism and ASGs provide the logical grouping that makes tier-based rules scalable and maintainable. VNet peering only connects virtual networks for private IP communication and does not itself filter or isolate tier traffic. Azure Policy is a governance/compliance tool for enforcing resource configurations, not a runtime traffic filter. Azure Firewall is a centralized, stateful network security service, but it is not the service used to isolate individual tiers within a VNet via subnet/NIC-level rules and workload grouping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network Security Groups (NSGs)

    Why this is correct

    Network Security Groups (NSGs) serve as the core stateful filtering mechanism inside Azure VNets, with rules evaluated by priority to permit or deny traffic based on the 5-tuple (source, destination, port, protocol, direction). Applying NSGs to subnets or VM NICs allows you to segment a three-tier application by isolating the web, business, and data tiers from each other. They are the native, default choice for tier isolation because they require no extra cost and offer granular control over east-west traffic.

  • ✗

    VNet peering

    Why it's wrong here

    VNet peering establishes connectivity between two separate virtual networks by routing traffic over the Azure backbone, enabling resources in one VNet to communicate with resources in another. It does not provide any filtering or security rules for traffic moving between tiers inside the same VNet, as its sole function is to extend network reach and routing. Consequently, peering is conceptually wrong for tier isolation because it addresses cross-VNet connectivity, not intra-VNet access control.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy operates at the Azure Resource Manager layer, assessing and enforcing attributes such as allowed VM SKUs, location constraints, or the presence of required tags, and it can even deploy a default NSG as a remediation task. However, it never sits in the data path, so it cannot inspect, accept, or block actual packets flowing between tiers. This makes Azure Policy a governance and compliance tool that can mandate security configuration but is not a mechanism that itself establishes tier isolation.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a fully managed, cloud-native firewall that provides centralized network and application-level protection, typically deployed in a hub VNet to filter traffic between spokes or outbound to the internet via user-defined routes. Using it purely to separate tiers within a single VNet is needlessly expensive and architecturally heavy, as features like FQDN filtering, threat intelligence, and forced tunneling are overkill for basic segmentation. NSGs already deliver the necessary stateful filtering for this scenario, and Azure Firewall's centralized logging and NAT capabilities do not replace the simplicity of per-tier NSG rules.

  • ✓

    Application Security Groups (ASGs)

    Why this is correct

    Application Security Groups (ASGs) are logical objects that group VM network interfaces by workload role, and they are referenced as source or destination in NSG rules to apply security policies consistently across dynamic VM sets. They are correct for tier isolation because they let you write rules such as 'allow frontend to access backend on port 1433' without hardcoding individual IP addresses, and membership updates propagate automatically. Although ASGs depend on NSGs to enforce the actual filtering, they are a recognized, recommended way to structure security rules for multi-tier applications because they reduce administrative overhead and enhance readability.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.