Question 1
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
* A virtual network named Vnet1
* A subnet named Subnet1 in Vnet1
* A virtual machine named VM1 that connects to Subnet1
* Three storage accounts named storage1, storage2, and storage3
You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other storage accounts.
Solution: You create a network security group (NSG) and associate the NSG to Subnet1.
Does this meet the goal?
Answer: No, this does not meet the goal.
Explanation:
Creating and associating an NSG to Subnet1 alone does not meet the requirement because:
- Incomplete solution: Simply creating an NSG and associating it to a subnet does nothing without configuring specific rules
- Default behavior: An empty NSG (or one with only default rules) allows all outbound traffic by default
- No storage access control: Without explicit outbound rules, the NSG would not prevent VM1 from accessing storage2 and storage3
What would be needed: To meet the goal, you would need to:
- Create an NSG with specific outbound rules that allow access to storage1 only
- Create a deny rule for outbound traffic to storage2 and storage3
- Or use service endpoint filtering (Advanced Network Security features)
- Associate the configured NSG to Subnet1
The question asks if simply creating and associating an NSG meets the goal, which is insufficient without proper rule configuration.






