exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 4 question 12 discussion

Actual exam question from Microsoft's AZ-700
Question #: 12
Topic #: 4
[All AZ-700 Questions]

You have an Azure virtual network named Vnet1.
You need to ensure that the virtual machines in Vnet1 can access only the Azure SQL resources in the East US Azure region. The virtual machines must be prevented from accessing any Azure Storage resources.
Which two outbound network security group (NSG) rules should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. a deny rule that has a source of VirtualNetwork and a destination of Sql
  • B. an allow rule that has the IP address range of Vnet1 as the source and destination of Sql.EastUS
  • C. a deny rule that has a source of VirtualNetwork and a destination of 168.63.129.0/24
  • D. a deny rule that has the IP address range of Vnet1 as the source and destination of Storage
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
milan92stankovic
Highly Voted 2 years, 4 months ago
Selected Answer: BD
Correct Answer - B & D
upvoted 9 times
...
pinchocr
Highly Voted 2 years, 4 months ago
Selected Answer: BD
Correct
upvoted 6 times
...
Sergovladi
Most Recent 3 months ago
Selected Answer: AB
Azure SQL is not part of Azure Storage. So you need to configure B first, with higher priority, to allow outbound, then create A deny rule with lower priority
upvoted 1 times
...
RemmyT
5 months ago
BD Two different types of resources : Azure SQL & Storage. NSG attached to subnets with the virtual machines. Rules: Azure SQL Source : Service Tag [Virtual Network], Destination : Service Tag [Sql.EastUS], Destination port ranges : *, Protocol : Any, Action : Allow, Priority: 100 Storages Source : Service Tag [Virtual Network], Destination : Service Tag [Storage], Destination port ranges : *, Protocol : Any, Action : Deny, Priority: 500
upvoted 1 times
...
kikocu
10 months, 1 week ago
Storage has nothing to do with SQL. For me the correct answer will be BC. We all agree B is correct. C because the Azure IP DNS resolution (168.63.129.16) is part of that range.
upvoted 2 times
...
Lazylinux
1 year, 1 month ago
Selected Answer: BD
Have to admit this question is typical MS question i.e. as dumb as can get here is why • Not much information is given about the vNET • Yes you can chose AB and answer is correct in terms of meeting the requirement for SQL i.e. stop access to all SQL instances except East USA, however A Deny rule needs to be of lower priority than the E-US rule to avoid blocking access to all SQL instances – example E-US rule priority 100 and block SQL 110 . However this solution doesn’t restrict the VMs from accessing the storage as per requirement • Yes you can chose BD, where B meets the requirement for e-US SQL and D meets the condition to block access to storage, however it doesn’t meet the requirement to prevent access to SQL resources in general If comes in the exam I would RELUCTANTLY chose BD
upvoted 2 times
...
Apptech
1 year, 6 months ago
I don't get it. Default outbound rule for NSG is "allow all". For this case for SQL access requirement we would need answers A + B. For storage access prevention we would also need answer D. If we would assume that outbound default NSG rule is "deny all" we would need allow rule for Sql.East and an allow rule for storage. So, in none of the scenarios we have a perfect answer option when just choosing 2 answers
upvoted 1 times
_fvt
1 year, 6 months ago
"Each correct answer presents part of the solution." the key is here. So; B - because you need to allow only VMs to SQL in specific East US region not All SQL (so not A). D - because as asked you need to deny VMs to all Storage. And you'll probably will add a deny rule if you had to complete "parts" of the solution.
upvoted 2 times
...
...
staffo
1 year, 8 months ago
A would work but question only mentions working with VNET1. It does not specifically mention other VNET's. D is more specific.
upvoted 1 times
...
omgMerrick
1 year, 8 months ago
Selected Answer: BD
B & D Explanation: Rule B allows traffic from the virtual machines in Vnet1 to the Azure SQL resources in the East US Azure region. Rule D denies traffic from the virtual machines in Vnet1 to any Azure Storage resources. Rule A is incorrect because it allows traffic from the virtual machines in Vnet1 to any destination that contains "Sql". Rule C is incorrect because it denies traffic from the virtual machines in Vnet1 to the Azure instance metadata service, which is not related to the given requirements.
upvoted 4 times
...
rac_sp
2 years, 3 months ago
Selected Answer: AB
Because Storage is NOT the same as SQL. There are completely different TAGs to SQL and STORAGE.SQL is database, Storage is Storage.
upvoted 1 times
cypher9
2 years, 3 months ago
I dont get it, why would you have a deny rule that has a source of VirtualNetwork?
upvoted 1 times
tng69
2 years, 2 months ago
Even if it's not what anyone would do, it is the solution closest to the ideal solution (which would be to set the VM's IP as source)
upvoted 1 times
...
...
cypher9
2 years, 3 months ago
reference?
upvoted 1 times
...
...
rac_sp
2 years, 3 months ago
shoud be A and B. Storage Tags is different from SQL( that is a database actually ). Also take a look that there is a TAG specifically for SQL which is a completely different resource than a Storage.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago