AZ-500 Secure networking Practice Question
You need to block inbound traffic from the internet to a specific subnet except for TCP port 443. Which Azure service should you use?
⚠ Common exam trap
Candidates often choose Azure Firewall (Option B) because it sounds like the most comprehensive security solution, but the question specifically asks for blocking inbound internet traffic to a subnet except for a single TCP port, which is a classic NSG use case—Azure Firewall is unnecessary and more expensive for this simple ACL requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network security group (NSG)
Network security groups (NSGs) are the correct choice because they provide stateful filtering of inbound and outbound traffic at the subnet or NIC level. By creating an inbound security rule that denies all traffic from the Internet (source 'Internet' service tag) and a higher-priority allow rule for TCP port 443, you can precisely block all inbound internet traffic except HTTPS. NSGs are the native Azure service for granular subnet-level access control lists (ACLs).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Web Application Firewall (WAF)
Why it's wrong here
Azure Web Application Firewall is a Layer 7 service that inspects HTTP/HTTPS traffic going to specific web applications, with managed rulesets targeting application-layer vulnerabilities such as SQL injection and cross-site scripting. It does not evaluate general network flows by IP addresses or ports, nor does it act as a perimeter filter for arbitrary subnet traffic. Because the requirement is to deny all inbound internet traffic to a subnet except one port, WAF lacks the necessary Layer 3/4 stateful filtering capability and would leave non-web protocols or non-HTTP traffic unaffected.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, cloud-based network security service that protects your virtual network resources. While it can certainly filter traffic based on ports and protocols, it operates at the network and transport layers, and its primary function is to act as a central security policy enforcement point for your virtual networks. The requirement to block *all* inbound traffic *except* for a specific port on a subnet is more granularly handled by Network Security Groups (NSGs) directly associated with the subnet or its network interface. Azure Firewall is tempting because it offers advanced threat protection and centralised management, making it ideal for protecting entire virtual networks or multiple VNets, rather than just a single subnet's inbound access.
- ✓
Network security group (NSG)
Why this is correct
A network security group is a stateful Layer 3/4 filtering component that binds directly to a subnet or network interface, allowing ordered allow and deny rules based on source/destination IP, port, and protocol. You can create a default deny rule for Internet inbound traffic and a higher-priority allow rule for the specific TCP/UDP port that must remain reachable, giving precise control over the subnet's attack surface. Because it is enforced at the subnet boundary and requires no per-application inspection overhead, this is the correct mechanism for blocking all Internet traffic except a single allowed port.
- ✗
Azure DDoS Protection
Why it's wrong here
Azure DDoS Protection provides always-on telemetry and adaptive tuning to absorb volumetric, protocol, and resource attacks targeting public IP addresses, such as SYN floods or UDP reflection attacks. It does not evaluate individual packets against custom allow/deny rules; its purpose is to maintain service availability during large-scale attacks rather than to enforce explicit port-level security policies. Therefore, while it is a useful complement, it cannot alone meet the requirement to selectively block all inbound Internet traffic except for a designated port.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.