You have an Azure virtual network named Vnet1. You need to ensure that the virtual machines in Vnet1 can access only the Azure SQL resources in the East US Azure region. The virtual machines must be prevented from accessing any Azure Storage resources. Which two outbound network security group (NSG) rules should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point. A. a deny rule that has a source of VirtualNetwork and a destination of Sql B. an allow rule that has the IP address range of Vnet1 as the source and destination of Sql.EastUS C. a deny rule that has a source of VirtualNetwork and a destination of 168.63.129.0/24 D. a deny rule that has the IP address range of Vnet1 as the source and destination of Storage  Suggested Answer: BD Reference: https://docs.microsoft.com/en-us/azure/virtual-network/service-tags-overview This question is in AZ-700 Designing and Implementing Microsoft Azure Networking Solutions Exam For getting Microsoft Certified: Azure Network Engineer Associate Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by Microsoft. The website does not contain actual questions and answers from Microsoft's Certification Exams. Trademarks, certification & product names are used for reference only and belong to Microsoft.
Please login or Register to submit your answer