Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a network security solution for a multi-tier application hosted in Azure. The front-end web tier must be accessible from the internet, but the back-end database tier must only accept traffic from the front-end tier. Which Azure service should you use to enforce this restriction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network Security Groups (NSGs)

Network Security Groups (NSGs) [CORRECT] are the right choice because they let you write inbound security rules that allow traffic to the database tier only from the front-end tier's subnet or NSG (using source service tags or NSG references), while denying all other inbound traffic including internet sources. NSGs operate at the subnet/NIC level in Azure and are the standard mechanism for micro-segmentation between tiers of an application. Azure Firewall (A) is a centralized, stateful firewall for controlling outbound/inbound traffic at the VNet level, but it is not the typical tool for simple tier-to-tier allow/deny rules and is more costly and complex than needed here. Azure Bastion (C) provides secure RDP/SSH access to VMs via the Azure portal and does not restrict application-tier traffic. Application Gateway (D) is a layer-7 web traffic load balancer and WAF for the front-end web tier, not a mechanism for restricting database-tier access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is not the primary service for enforcing traffic restrictions between subnets within the same virtual network for distinct application tiers. Its strength lies in providing centralised network security policies, inspecting traffic at the virtual network perimeter, between VNets, or to/from the internet. It is tempting as a general firewall, and would be correct for securing overall ingress/egress traffic for the entire application environment or managing traffic between separate application VNets.

  • ✓

    Network Security Groups (NSGs)

    Why this is correct

    Network Security Groups are the fundamental Azure service for filtering traffic between subnets in the same virtual network. They are stateful and contain inbound and outbound security rules that evaluate source/destination IP, port, and protocol, allowing you to permit only required traffic between tiers (e.g., web to app on 443). By default, all VNet traffic is allowed, so explicit NSG rules are required to enforce least-privilege segmentation.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion is a fully managed platform service that provides secure, browser-based RDP/SSH connectivity to virtual machines through the Azure portal, eliminating the need for public IP addresses. It acts as a jump host and does not inspect or filter traffic between subnets or application tiers; its role is purely management-plane remote access. Therefore, it cannot enforce network segmentation policies.

  • ✗

    Application Gateway

    Why it's wrong here

    Application Gateway is a layer 7 load balancer that provides TLS termination, cookie-based session affinity, URL path routing, and a web application firewall. It operates at the application layer and routes traffic to backend pools, but it does not perform stateful IP/port filtering between subnets, nor does it restrict east-west traffic between application tiers. Its security value is for ingress traffic, not subnet-level segmentation.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.