NSGs, ASGs and Flow Logs
Network security questions test network security groups, application security groups, inbound and outbound rules, effective security rules, Bastion, and flow logs.
How to study for AZ-700
Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.
Core concepts
Concept 1
NSGs, ASGs and Flow Logs questions test Azure networking design and troubleshooting choices rather than memorized portal paths.
Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.
Concept 2
The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.
Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.
Concept 3
Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.
Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.
Risk pitfalls and guardrails
Confusing DNS resolution with routing or security filtering.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Memory anchors
Network Security Group
A network security group filters inbound and outbound traffic for subnets or network interfaces.
Security Rule
A security rule allows or denies traffic by priority, direction, protocol, source, destination, and port.
Application Security Group
An application security group groups VM network interfaces for rule targeting.
Effective Security Rules
Effective security rules show the combined NSG rules applied to a network interface.
Priority
NSG rule priority controls evaluation order, with lower numbers evaluated first.
Default Rule
Default NSG rules allow VNet and load balancer traffic and deny other inbound traffic.
Azure Bastion
Azure Bastion provides browser-based RDP and SSH access without exposing public inbound ports on VMs.
Flow Logs
Virtual network flow logs record IP traffic metadata for analysis and security monitoring.
IP Flow Verify
IP flow verify checks whether a packet is allowed or denied by security rules.
Remote Administration
Remote administration should use secure, audited access paths rather than broad public management ports.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
An NSG has an inbound allow rule at priority 200 and an inbound deny rule at priority 100 for the same flow. What happens?
A VM NIC and its subnet each have an NSG. What must be true for inbound traffic to reach the VM?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
