Examsnet
Unconfined exams practice
Home
Exams
Banking Entrance Exams
CUET Exam Papers
Defence Exams
Engineering Exams
Finance Entrance Exams
GATE Exam Practice
Insurance Exams
International Exams
JEE Exams
LAW Entrance Exams
MBA Entrance Exams
MCA Entrance Exams
Medical Entrance Exams
Other Entrance Exams
Police Exams
Public Service Commission (PSC)
RRB Entrance Exams
SSC Exams
State Govt Exams
Subjectwise Practice
Teacher Exams
SET Exams(State Eligibility Test)
UPSC Entrance Exams
Aptitude
Algebra and Higher Mathematics
Arithmetic
Commercial Mathematics
Data Based Mathematics
Geometry and Mensuration
Number System and Numeracy
Problem Solving
Board Exams
Andhra
Bihar
CBSE
Gujarat
Haryana
ICSE
Jammu and Kashmir
Karnataka
Kerala
Madhya Pradesh
Maharashtra
Odisha
Tamil Nadu
Telangana
Uttar Pradesh
English
Competitive English
Certifications
Technical
Cloud Tech Certifications
Security Tech Certifications
Management
IT Infrastructure
More
About
Careers
Contact Us
Our Apps
Privacy
Test Index
Microsoft Azure Administrator Associate AZ 104 Practice test 5
Show Para
Hide Para
Share question:
© examsnet.com
Question : 14
Total: 50
You have an Azure subscription that contains the resources in the following table.
Name
Type
Details
VNet1
Virtual network
Not applicable
Subnet1
Subnet
Hosted on VNet1
VM1
Virtual machine
On Subnet1
VM2
Virtual machine
On Subnet1
VM1 and VM2 are deployed from the same template and host line-of-business applications.
You configure the network security group (NSG) shown in the exhibit. (Click the Exhibit tab.)
Inbound security rules
PRORITY
NAME
PORT
PROTOCOL
SOURCE
DESTINATION
ACTION
100
Port_80
80
TCP
Internet
Any
🔴 Deny
65000
AllowVnetinBound
Any
Any
VirtualNetwork
VirtualNetwork
🟢 Allow
65001
Allow AzureLoadBalancerlnBound
Any
Any
AzureLoadBalancer
Any
🟢 Allow
65500
DenyAllInBound
Any
Any
Any
Any
🔴 Deny
Outbound security rules
PRIORITY
NAME
PORT
PROTOCOL
SOURCE
DESTINATION
ACTION
100
A DenyWebSites
80
TCP
Any
Internet
🔴 Deny
65000
AllowVnetOutBound
Any
Any
VirtualNetwork
VirtualNetwork
🟢 Allow
65001
AllowInternetOutBound
Any
Any
Any
Internet
🟢 Allow
65500
DenyAllOutBound
Any
Any
Any
Any
🔴 Deny
You need to prevent users of VM1 and VM2 from accessing websites on the Internet over TCP port 80.
What should you do?
Disassociate the NSG from a network interface
Change the Port_80 inbound security rule.
Associate the NSG to Subnet1.
Change the DenyWebSites outbound security rule.
Validate
Solution:
Explanation:
You can associate or dissociate a network security group from a network interface or subnet.
The NSG has the appropriate rule to block users from accessing the Internet. We just need to associate it with Subnet1.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/manage-network-security-group
© examsnet.com
Go to Question:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
Prev Question
Next Question