Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

You need to allow inbound HTTP traffic from the internet to a specific VM in a VNet. The VM is in a subnet with an NSG. What is the correct way to configure access?

⚠ Common exam trap

Many candidates confuse Azure Firewall (a centralized, cross-subnet service) with NSGs (a subnet/NIC-level firewall) and incorrectly assume a firewall is required for inbound internet traffic, when in fact NSGs are the correct and simpler solution for allowing HTTP to a specific VM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an inbound security rule in the NSG to allow HTTP traffic.

Network Security Groups (NSGs) operate at the subnet or NIC level and act as a stateful firewall for traffic entering or leaving Azure resources. To allow inbound HTTP (TCP port 80) traffic from the internet to a specific VM, you must add an inbound security rule to the NSG associated with the VM's subnet or NIC, specifying the source as 'Internet', destination port 80, and protocol TCP. This is the direct and correct method for controlling traffic to a VM within a VNet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a rule in Azure Firewall to allow HTTP traffic to the VM.

    Why it's wrong here

    An Azure Firewall rule alone cannot permit inbound HTTP traffic to a VM unless the firewall is explicitly deployed in the network path and traffic is routed to it via user-defined routes (UDRs) or a hub-spoke architecture. Even then, you must also configure DNAT or an application rule with the appropriate public IP mapping, making it an unnecessarily complex solution for simply allowing port 80 to a single VM. In contrast, an NSG directly attached to the VM's subnet or NIC provides immediate, stateful filtering without additional routing overhead.

  • ✗

    Enable Azure DDoS Protection on the VNet.

    Why it's wrong here

    Azure DDoS Protection provides always-on traffic monitoring and mitigation of volumetric, protocol, and resource-layer attacks, but it does not contain allow/deny rules for specific ports or protocols. It only acts when an attack is detected and cannot be configured to 'allow' HTTP inbound traffic; its purpose is to protect availability, not to open a port. Without an NSG or firewall rule permitting port 80, the traffic will still be dropped at the network layer.

  • ✗

    Configure Azure Traffic Manager to route traffic to the VM.

    Why it's wrong here

    Azure Traffic Manager is a DNS-based traffic load balancer that routes requests based on routing methods like priority or performance, but it does not filter packets at a network layer nor does it modify NSG or subnet security rules. It simply resolves a domain to an endpoint IP; if the VM lacks an inbound NSG rule allowing HTTP, the connection will still be blocked after DNS resolution. Thus, Traffic Manager cannot by itself enable inbound HTTP traffic to a VM.

  • ✓

    Add an inbound security rule in the NSG to allow HTTP traffic.

    Why this is correct

    An NSG is a stateful, Layer-3/4 filter that can be associated with a VM's NIC or its subnet to control inbound and outbound traffic. Adding an inbound security rule with source 'Internet', destination port 80, protocol TCP, and action 'Allow' will permit HTTP traffic to reach the VM, provided the VM has a public IP or is behind a load balancer with proper port forwarding. This is the standard, least-privilege solution for allowing a single port to a VM from the internet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.