exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 4 question 17 discussion

Actual exam question from Microsoft's AZ-700
Question #: 17
Topic #: 4
[All AZ-700 Questions]

HOTSPOT -
You have an Azure subscription that contains the virtual machines shown in the following table.

VNet1 and VNet2 are NOT connected to each other.
You need to block traffic from SQL Server 2019 to IIS by using application security groups. The solution must minimize administrative effort.
How should you configure the application security groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: 2 -
All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in.
We need one application security group for each of the two virtual networks.

Box 2: 3 -
One network assignment in VNet1. Two network assignments in VNET2.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alessandro365
Highly Voted 2 years, 6 months ago
2 ASGs e 3 assignments, aswer is correct. "All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in." https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups the ASG needs to be associated with the network card of the VMs, so there are 3 associations
upvoted 15 times
Ayokun
2 years, 1 month ago
But being that is requested the configuration of the ASG only on the SQL vm's to minimize administrative effort the answer should be halfed: 4 asg = 2 (onlysql) 6 assigments per nic = 3 (only sql)
upvoted 2 times
...
Ayokun
2 years, 1 month ago
Hence being the ASG associated per NIC it should be 6 the second answer.
upvoted 1 times
...
...
keilah123
Highly Voted 2 years, 1 month ago
2 ASG and 2 ASG assignments The question is looking for minimum. VNET 1: Create 1 ASG for SQL. Create outbound deny rule and assign to SQL1 Nic VNET2: Create 1 ASG for IIS. Create inbound deny rule and assign to Web3 Nic
upvoted 11 times
Apptech
2 years ago
Yes, but question also says: "block traffic from SQL Server 2019 to IIS". With your ASG for IIS you deny any kind of instance / service to access IIS.
upvoted 4 times
Ditka
1 year, 8 months ago
I think it would be: VNET 2: Create 1 ASG for SQL inbound deny and assign to IIS NIC.
upvoted 1 times
Ditka
1 year, 8 months ago
Total 2 ASGs and 2 ASG assignments.
upvoted 1 times
...
ironbornson
1 year, 6 months ago
On SQL Traffic will use a random source port and dst-port 80,443. If you apply an ASG to IIS you will have no way to identify if traffic is coming from SQL or not. The only way to block VM-SQL to VM-IIS is to create a rule blocking ASG for VM-SQL like this: Direction: outbound, Source:ASG-VM, Dst: (you can put IIS IP or IIS ports), Action: deny TL;DR: 2 ASG and 3 assignments
upvoted 2 times
...
...
...
Rododendron2
1 year, 4 months ago
Not correct due to not correctly understood Qeuestion. Once again - Question is looking for minimum administrative effort, not for minimal number of ASG/assignments.
upvoted 1 times
...
...
xRiot007
Most Recent 4 days, 5 hours ago
Correct answer: - 2 AGSs - an application security group can be assigned at the level of the VNet. We have 2 VNets, so 2 ASGs. https://www.cayosoft.com/azure-security-best-practices/azure-application-security-group/ - 3 assignments - we have 3 IIS resources, so we need to assign 3 NICs to the ASGs, so we need to block each of them from reaching SQL with a deny NSG rule per ASG
upvoted 1 times
...
0dc759b
6 months, 3 weeks ago
One ASG ( all SQL VM) per vnet. in each Web VM's NSG (3 IIS Nic) you need to assign that ASG.
upvoted 1 times
...
_cloudio_
1 year ago
1 ASG and 2 assignments. Explanation: Vnet 1 does not need ASG because there's only 1 SQL server, so there's no point in creating ASG. Vnet 2 has 2 SQL servers that need to be added to 1 ASG. So, 2 assignments (1 for each SQL server), and 1 ASG.
upvoted 1 times
...
jayek
1 year ago
https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups#:~:text=You%20can%27t%20add%20network%20interfaces%20from%20different%20virtual%20networks%20to%20the%20same%20application%20security%20group.
upvoted 1 times
...
CiscoExam
1 year, 2 months ago
2 ASGs and 6 Assignments ASGs are per Resource Group and not per VNET. So, one for each app type (iis & sql) There are 6 VMs. Each NIC needs to be told what ASG it's part of. Then one NSG applied to both VNETs with one rule. Src-SQL-ASG ; Dst-IIS-ASG ; Deny
upvoted 1 times
...
Webesciaki
1 year, 3 months ago
2 ASG / 3 assignments: 1x ASG for vnet1/sql 1x ASG for vnet2/sql now assignments: 1) 1st sql server in vnet1 2) 1st sql server in vnet 2 3) 2nd sql server in vnet 2 then subnet level NSGs with inbound rule (source SQL application group -> dst any > deny)
upvoted 7 times
cerifyme85
1 year, 1 month ago
then subnet level NSGs with inbound rule (source SQL application group -> dst any > deny) Shoudln't this be: then subnet level NSGs with inbound rule (source SQL application group -> dst IIS Subnets > deny )?
upvoted 1 times
...
...
occupatissimo
1 year, 11 months ago
2 & 3 key word is "minimize administrative effort", and remember goal is to block sql. so work only with outbound rule applied to SQL server, when building the rule will'have the tcp-80, doesn't matter which destination (use any), for sure IIS server are in. in this case 2 ASG (1 each vnet) for sql are required and 3 ssignment (1 each sql server nic).
upvoted 3 times
occupatissimo
1 year, 11 months ago
or think in this way too communication between vnet is deny due to degault rule in nsg, so only to block traffic between subnet in the sane vnet. Assuming in the sql subnet the source as any and the dest the ASG necessary is for web server only, tis in each vnet, so 2 ASG in total. Associate then the three web server nics to them.
upvoted 2 times
...
...
guchao2000
2 years ago
NSG and ASG can be used in different vnet. Tested.
upvoted 3 times
...
iVath
2 years ago
it's only required : from SQL Server 2019 to IIS. what about these 3 ASG assignments: (Source=Vnet1/Sub1/SQL, Destination=Vnet1/Sub1/IIS, Access=Deny) (Source=Vnet2/Sub1/SQL, Destination=Vnet2/Sub1/IIS, Access=Deny) (Source=Vnet2/Sub2/SQL, Destination=Vnet2/Sub1/IIS, Access=Deny)
upvoted 3 times
...
TJ001
2 years, 2 months ago
No of ASGs [ANS 4 ] - So there are 2 VNETs, 2 types of applications in both VNET one of type IIS and one of type SQL. The best practice is to use ASG assignment for both app types... which means 2 ASGs per VNET = 4 ASGs required. Note ASG cannot reference multiple VNETs 2)No of associations [Ans 6] ? - The assignment is at subnet level, so we could do add either an outbound rule for SQL server subnet or an inbound rule at IIS server subnet or both .. Assume we are adding only one rule (either inbound or outbound) and the question asks minimum no of assignments - In VNET 1 add an outbound rule for Subnet 1 to deny traffic from SQL ASG to IIS ASG - In VNET 2 add an inbound rule for Subnet 1 to deny traffic from SQL ASG to IIS ASG so 1 NSG rule per VNET is sufficient to introduce the control.. To meet this solution the ASG needs to associated to all the VMs in all VNET ... so total 6 associations is needed (if by 'association' it means attaching ASG to VM NIC)
upvoted 1 times
TJ001
2 years, 2 months ago
it appears the option does not have an ideal set up and it looks it is only considering attaching ASG to SQL component in which case ....we could half the consideration above to conclude the answers as 2 ASG and 3 assignments ...not elegant/scalable approach but will have go with that
upvoted 4 times
...
...
Goofer
2 years, 3 months ago
I think you must create one ASG for all IIS NIC's and one NSG on al SQL server NICs In the NSG Block all outgoing traffic to IIS ASG. (You need only to block traffic from SQL Server 2019 to IIS) 1 ASG (for all IIS NICS) 1 NSG (for all SQL NICs) It's not a pretty solution, but with the least administrative effort
upvoted 3 times
Goofer
2 years, 3 months ago
If all network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. You need 2 ASG's
upvoted 1 times
...
...
mhmyz
2 years, 3 months ago
2 ASGs How to make the IIS side (receiving side) an application group, How to make the SQL side (sending side) an application group There are two, and both methods create one application group for each VNET, so there are two application groups. 2 Assignments In VNET1, the IIS side is set as an application group, and transmission to the IIS application group can be suppressed in the transmission traffic of Subnet1 or NIC of SQL1. In VNET2, the SQL side is set as an application group, and reception to the IIS application group should be suppressed in the reception traffic of Subnet1 or NIC of Web3.
upvoted 4 times
Goofer
2 years, 3 months ago
How do you block traffic between Web1 and SQL1. They are on the same subnet.
upvoted 2 times
palthainon
2 years, 1 month ago
NSG's can be assigned at the NIC level.
upvoted 1 times
...
...
...
NoeHdzMll
2 years, 4 months ago
Confuse answer, the correct answer is to have 2 ASG and 3 associations per VNET, in this case, there are 2 VNETs. Total 4 ASG and 6 associations, one association per VM
upvoted 6 times
TJ001
2 years, 2 months ago
agree but the options does not have 4 ASG
upvoted 3 times
daemon101
1 year, 9 months ago
I also agree. If only vnet1 contains IISs and Vnet2 has SQL then it will only need two ASGs.
upvoted 1 times
...
...
...
Prutser2
2 years, 6 months ago
answer is correct
upvoted 4 times
...
sapien45
2 years, 6 months ago
By network security group assigement, they mean how many Microsoft SQL servers assigned within an Application secuirty grroup
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago