Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "protocol": "Any",
    "sourceAddresses": ["*"],
    "destinationAddresses": ["*"],
    "destinationPorts": ["*"],
    "sourcePorts": ["*"],
    "access": "Allow",
    "priority": 100,
    "direction": "Inbound",
    "ruleType": "BasicRule"
  }
}
```

You are reviewing an NSG rule as shown in the exhibit. This rule is applied to a subnet containing web servers. What is the security implication of this rule?

⚠ Common exam trap

The trap here is that candidates may focus on the rule's name or description (e.g., 'AllowHTTP') and assume it only permits HTTP traffic, overlooking the actual rule properties that set source, destination, and protocol to 'Any'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It allows all inbound traffic, creating a security risk.

The NSG rule shown in the exhibit has a source and destination of 'Any' and an action of 'Allow' for all ports and protocols. This effectively permits all inbound traffic from any source to the subnet, bypassing any intended security restrictions. Such a configuration exposes the web servers to unrestricted network access, including malicious traffic, creating a significant security risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It restricts inbound traffic to TCP only.

    Why it's wrong here

    The NSG rule's protocol is set to 'Any', not specifically TCP. A protocol value of Any means the rule applies to TCP, UDP, ICMP, and every other IP protocol. Since there is no protocol filter limiting the rule to TCP, the statement that it restricts inbound traffic to TCP only is false.

  • ✓

    It allows all inbound traffic, creating a security risk.

    Why this is correct

    The rule specifies 'Allow' as the action with source, destination, protocol, and port range all set to 'Any'. This combination creates a rule that permits all inbound traffic from any source to any port on any protocol. Such a rule overrides the default NSG deny rules and exposes the associated resources to the entire internet, which is a significant security risk.

  • ✗

    It blocks all inbound traffic except HTTP.

    Why it's wrong here

    The rule's action is 'Allow', not 'Deny', and its scope is not limited to HTTP traffic. The rule permits all inbound traffic regardless of protocol or port, so it cannot block any traffic. In contrast, a rule that blocks all traffic except HTTP would need an explicit 'Deny' action for other protocols and a specific 'Allow' for port 80/TCP.

  • ✗

    It restricts inbound traffic to HTTP only.

    Why it's wrong here

    The rule does not contain any port or protocol condition that would restrict traffic to HTTP. HTTP typically uses TCP port 80, but this rule has 'Port Range: Any' and 'Protocol: Any', meaning it allows HTTP as well as all other services such as HTTPS, RDP, SSH, and custom applications. There is no 'HTTP-only' filter present in the rule.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.