Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 68 discussion

Actual exam question from Microsoft's AZ-104
Question #: 68
Topic #: 2
[All AZ-104 Questions]

You have an Azure subscription that contains 10 virtual machines, a key vault named Vault1, and a network security group (NSG) named NSG1. All the resources are deployed to the East US Azure region.

The virtual machines are protected by using NSG1. NSG1 is configured to block all outbound traffic to the internet.

You need to ensure that the virtual machines can access Vault1. The solution must use the principle of least privilege and minimize administrative effort

What should you configure as the destination of the outbound security rule for NSG1?

  • A. an application security group
  • B. a service tag
  • C. an IP address range
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Iszy
Highly Voted 1 year, 9 months ago
The correct answer is B. a service tag. In order to ensure that the virtual machines can access Vault1 while also using the principle of least privilege and minimizing administrative effort, you should configure a service tag as the destination of the outbound security rule for NSG1. Service tags represent a group of IP addresses associated with Azure PaaS and SaaS services. By specifying a service tag as the destination of the outbound security rule, you can allow the virtual machines to access Vault1 without having to manually specify the IP addresses of Vault1. This reduces administrative effort and ensures that the virtual machines are only able to access Vault1, rather than any other internet destination.
upvoted 72 times
...
Muffay
Highly Voted 1 year, 9 months ago
Selected Answer: B
B - Service Tag is correct. https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview#available-service-tags "AzureKeyVault" tag can be used in outbound NSGs.
upvoted 26 times
...
SeMo0o0o0o
Most Recent 1 month ago
Selected Answer: B
B is corerct
upvoted 1 times
...
3c5adce
4 months, 3 weeks ago
B. a service tag Service tags in Azure simplify the security definition for Azure services, allowing you to define network access controls on NSG rules without having to know the specific IP addresses. Specifically, you can use the "AzureKeyVault" service tag to enable virtual machines to access Azure Key Vault services like Vault1, securely and efficiently. This approach directly aligns with the principle of least privilege by restricting outbound traffic specifically to the Azure Key Vault service, thereby minimizing broader internet access and reducing administrative complexity.
upvoted 1 times
...
Amir1909
6 months, 2 weeks ago
B is correct
upvoted 1 times
...
tripleaholic
10 months, 2 weeks ago
similar as question 32 on https://www.examtopics.com/exams/microsoft/az-104/view/51/
upvoted 1 times
...
Rams786
1 year ago
This question was on my exam on 22 Sep 2023. scored 900 i answered B
upvoted 5 times
...
iamchoy
1 year ago
Selected Answer: B
To ensure that the virtual machines can access Vault1 while adhering to the principle of least privilege and minimizing administrative effort, you should use Azure's built-in service tags. These service tags represent a group of IP address prefixes from a given Azure service. When you want to allow communication between Azure services and resources, using service tags reduces the complexity of IP address management. For your requirement, Azure provides a service tag specifically for Azure Key Vault: AzureKeyVault. By using this service tag, you ensure that your virtual machines can only access Azure Key Vault in the East US region and not other unrelated internet resources. Therefore, the correct answer is: B. a service tag.
upvoted 1 times
...
iamchoy
1 year ago
Selected Answer: B
B most voted.
upvoted 1 times
...
Aquintero
1 year, 2 months ago
Selected Answer: B
Una etiqueta de servicio representa un grupo de prefijos de direcciones IP de un servicio de Azure determinado. Microsoft administra los prefijos de direcciones que la etiqueta de servicio incluye y actualiza automáticamente dicha etiqueta a medida que las direcciones cambian, lo que minimiza la complejidad de las actualizaciones frecuentes en las reglas de seguridad de red. Puede usar etiquetas de servicio para definir controles de acceso a la red en grupos de seguridad de red, Azure Firewall y rutas definidas por el usuario. Use etiquetas de servicio en lugar de direcciones IP específicas cuando cree reglas de seguridad y rutas.
upvoted 4 times
...
BJS_AzureExamTopics
1 year, 2 months ago
Service tag is the least work. MSFT answers are ALWAYS the least administrative effort answers, and there will usually be only one choice that stands out.
upvoted 2 times
...
UmbongoDrink
1 year, 7 months ago
Selected Answer: B
B - Service Tag is correct. https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview#available-service-tags "AzureKeyVault" tag can be used in outbound NSGs.
upvoted 3 times
...
zellck
1 year, 8 months ago
Selected Answer: B
B is the answer. A service tag represents a group of IP address prefixes from a given Azure service. Microsoft manages the address prefixes encompassed by the service tag and automatically updates the service tag as addresses change, minimizing the complexity of frequent updates to network security rules. You can use service tags to achieve network isolation and protect your Azure resources from the general Internet while accessing Azure services that have public endpoints. Create inbound/outbound network security group rules to deny traffic to/from Internet and allow traffic to/from AzureCloud or other available service tags of specific Azure services.
upvoted 3 times
...
zellck
1 year, 8 months ago
Selected Answer: B
B is the answer. https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview A service tag represents a group of IP address prefixes from a given Azure service. Microsoft manages the address prefixes encompassed by the service tag and automatically updates the service tag as addresses change, minimizing the complexity of frequent updates to network security rules. You can use service tags to achieve network isolation and protect your Azure resources from the general Internet while accessing Azure services that have public endpoints. Create inbound/outbound network security group rules to deny traffic to/from Internet and allow traffic to/from AzureCloud or other available service tags of specific Azure services.
upvoted 2 times
zellck
1 year, 8 months ago
You should configure a service tag as the destination of the outbound security rule for NSG1. This will allow the virtual machines to access Vault1 while still adhering to the principle of least privilege and minimizing administrative effort. A service tag represents a group of Azure resources that are identified by a common tag, in this case, the key vault. By configuring the outbound rule to allow traffic to the key vault service tag, you are ensuring that only traffic to the key vault is allowed, and not to any other internet destinations. This is more secure and efficient than specifying an IP address range or configuring an application security group.
upvoted 4 times
...
...
Muffay
1 year, 9 months ago
B - Service Tag is correct. https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview#available-service-tags "AzureKeyVault" tag can be used in outbound NSGs.
upvoted 3 times
...
khaled_razouk
1 year, 9 months ago
Selected Answer: B
To ensure that the virtual machines can access Vault1 while minimizing administrative effort and using the principle of least privilege, you should configure a service tag as the destination of the outbound security rule for NSG1.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...