exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 3 question 63 discussion

Actual exam question from Microsoft's AZ-500
Question #: 63
Topic #: 3
[All AZ-500 Questions]

HOTSPOT
-

You have an Azure subscription that contains the virtual machines shown in the following table.



VNET1, VNET2, and VNET3 are peered with each other.

You perform the following actions:

• Create two application security groups named ASG1 and ASG2 in the West US region.
• Add the network interface of VM1 to ASG1.

The network interfaces of which virtual machines can you add to ASG1 and ASG2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
r_git
Highly Voted 2 years, 1 month ago
Tested in lab. ASGs can be assigned to VMs that are in the same region the ASG is in AND the same VNET as the first VM that is assigned to it is in. ASG1 - VM2 ASG1 is in WEST US and VM1 on VNET1 is assigned to it, so ASG1 can only be assigned to VMs that are in VNET1. ASG2 - VM1, VM2, VM4 ASG2 is in WEST US and currently has no VMs assigned to it. So ASG1 can be assigned to VM1 and VM2 in VNET1 OR VM4 in VNET3. But not VM1/2 AND VM4 all at the same time.
upvoted 28 times
massnonn
1 year, 10 months ago
why not ASG- VM2 AND VM4 only? VM1 is just assigned
upvoted 1 times
epomatti
1 year, 3 months ago
A VM can be a member of multiple ASGs.
upvoted 3 times
...
...
epomatti
1 year, 3 months ago
Tested and confirmed. ASG2 - VM1, VM2, VM4 Documentation does not make that explicit, but ASG and VM must be in the same region as well. After you add the first network card, then all NICs added after that must also be in the same VNET.
upvoted 1 times
...
...
Nick66
Highly Voted 2 years, 3 months ago
ASG1: VM2 only ASG2: VM1, VM2, VM4 A Virtual Machine can be attached to more than one Application Security Group. This helps in cases of multi-application servers. There are only two requirements: • All network interfaces used in an ASG must be within the same VNet • If ASGs are used in the source and destination, they must be within the same VNet
upvoted 11 times
...
Srirupam
Most Recent 5 months, 1 week ago
ASG1- VM2 & VM4 ASG2-VM1,VM2,VM4
upvoted 1 times
...
Goke282
1 year, 1 month ago
The answer is correct: ASG1: VM2 Only ASG2: VM1, VM2, VM3, VM4 Explanation according to Copilot: Azure Virtual Machines (VMs) can be assigned to Application Security Groups (ASGs) regardless of their region. ASGs allow you to group VMs and define network security policies based on those groups. Here are some key points: Application Security Groups (ASGs): Enable you to configure network security as a natural extension of an application’s structure. Group VMs and define network security policies based on those groups. Reuse security policies at scale without manual maintenance of explicit IP addresses. Handle the complexity of explicit IP addresses and multiple rule sets. Example: Consider an example where NIC1 and NIC2 are members of the AsgWeb ASG, NIC3 is a member of the AsgLogic ASG, and NIC4 is a member of the AsgDb ASG. Each NIC can be a member of multiple ASGs, up to Azure limits. Network interfaces apply rules based on the ASGs they belong to.
upvoted 1 times
...
gen33
1 year, 4 months ago
region constraint does not apply so the proposed answer is correct
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Tested in the lab the ASG was in a UK West region and I could not add the NIC which was in North Europe Region to it so all VMs in the same region as the ASG could be added only its VM1,2,4
upvoted 1 times
...
femzy
1 year, 4 months ago
Application Security Groups (ASGs) are used within a single network security group (NSG). ASGs are regional resources and can only be used within the same Azure region where they are created. ASG1: VM2 and VM4 only (because they are in the same region as ASG1) ASG2: VM1, VM2, and VM4 only (because they are all in the West US region and can be grouped together in ASG2)
upvoted 2 times
...
flafernan
1 year, 5 months ago
ASG1 - VM2 Only Because it is the only one that is in the same VNET as VM1. ASG2 - VM2 VM3 and VM4 Only Following the rule that you can only associate an ASG with a single VNET, and that even if Virtual Machines (VMs) are in the same Virtual Network (VNET), you can associate each VM with a different Application Security Group (ASG) . This would already exclude VM1 from ASG2 which is already associated with VNET1. There would then only be the possibility of VM2 VM3 and VM4 Only.
upvoted 1 times
pentium75
8 months, 4 weeks ago
VM1 could be member of multiple ASGs, you can add it to ASG2 as long as that is empty.
upvoted 1 times
...
...
wardy1983
1 year, 5 months ago
ASG1: VM2 only ASG2: VM1, VM2, VM4 A Virtual Machine can be attached to more than one Application Security Group. This helps in cases of multiapplication servers. There are only two requirements: • All network interfaces used in an ASG must be within the same VNet • If ASGs are used in the source and destination, they must be within the same VNet
upvoted 1 times
...
TheProfessor
1 year, 6 months ago
Can anybody please explain why ASG2: VM1 VM2 VM3 VM4 VM1 and VM2 are in one Vnet where VM4 is in another Vnet. As per my understanding, VMs need to be under same Vnet. In that case, only VM4 should in ASG2.
upvoted 2 times
pentium75
8 months, 4 weeks ago
Yes, "VMs need to be under same Vnet", but ASG2 is currently empty. Thus you can add any VM to it. Once you added the first VM, THEN you can only add VMs from the same VNet.
upvoted 1 times
...
...
Self_Study
1 year, 8 months ago
On my exam today. The question asked where ASG1 only can be assigned.
upvoted 5 times
...
ITTesters
1 year, 11 months ago
Tip note from the Azure Portal when you try to add a ASG to a VM NIC: "Showing only application security groups in the same region as the network interface. If you choose more than one application security group, they must all exist in the same virtual network."
upvoted 4 times
...
zellck
1 year, 12 months ago
ASG1: VM2 only ASG2: VM1, VM2 and VM4 only https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You can't add network interfaces from different virtual networks to the same application security group.
upvoted 5 times
xRiot007
9 months, 1 week ago
Your explanation and answer make no sense. VM4 is in VNET3, while WM1 is in VNET1.
upvoted 1 times
...
...
Tecenvi
2 years ago
There is not limit to the region... An ASP can has more than one NIC but all must be in the same vNet. https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups
upvoted 1 times
...
majstor86
2 years, 1 month ago
ASG1 - VM2 ASG2 - VM1, VM2, VM4
upvoted 4 times
stepman
1 year, 12 months ago
I chose this. On exam 4/27 along with the new user experience exam
upvoted 3 times
zellck
1 year, 12 months ago
what new user experience did you get?
upvoted 2 times
...
...
...
another2
2 years, 2 months ago
Correct answer is : asg1 - VM2 asg2 - VM1, VM2, VM4 when ASG contains VM, you can only add other vm's that are in the same virtual network in this case VM2, if ASG(asg2) has not previously added vm's , you can add them only from the same Region, in this case US West.
upvoted 6 times
another2
2 years, 2 months ago
P.S peering not changing anything in this case.
upvoted 5 times
...
...
AzureJobsTillRetire
2 years, 3 months ago
Box1: VM2 only Add the network interface of VM1 to ASG1. VM1 is in VET1, all available ASGs must be in VNET1. Box2: VM2 and VM4 ASG2 is in the West US region, and it has not been attached to any NIC yet. It can be attached to NICs in the West US region, and both VM2 and VM4 are in the West US region.
upvoted 2 times
AzureJobsTillRetire
2 years, 3 months ago
Azure security groups can't be moved from one region to another. You can however, use an Azure Resource Manager template to export the existing configuration and security rules of an NSG. You can then stage the resource in another region by exporting the NSG to a template, modifying the parameters to match the destination region, and then deploy the template to the new region. https://learn.microsoft.com/en-us/azure/virtual-network/move-across-regions-nsg-portal
upvoted 1 times
AzureJobsTillRetire
2 years, 3 months ago
Sorry I copied the wrong ref, pls, disregard this particular comment. I will upload the right ref soon
upvoted 1 times
...
...
AzureJobsTillRetire
2 years, 3 months ago
All network interfaces assigned to an application security group have to exist in the same virtual network that the first network interface assigned to the application security group is in. For example, if the first network interface assigned to an application security group named AsgWeb is in the virtual network named VNet1, then all subsequent network interfaces assigned to ASGWeb must exist in VNet1. You cannot add network interfaces from different virtual networks to the same application security group. https://learn.microsoft.com/en-us/azure/virtual-network/application-security-groups
upvoted 2 times
...
AzureJobsTillRetire
2 years, 3 months ago
Sorry my bad. I think Box2 is VM1, VM2 and VM4. The catch is that you cannot add VM1/VM2 and VM4 to ASG2 at the same time. Once you add VM1 or VM2 to ASG2, VM4 is out. Once you add VM4 to ASG2, VM1 and VM2 are out.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago