To let VM1 reach a new Azure SQL Managed Instance, create a dedicated delegated subnet, associate an NSG, and attach a route table

Plan and implement security for Azure SQL Database and Azure SQL Managed Instance
Answer Correct answer: A, D, E — Create a dedicated delegated subnet for SQL1, associate an NSG, and attach a route table so VM1 can reach the managed instance.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a single subnet. The subscription contains a virtual machine named VM1 that is connected to VNet1. You plan to deploy an Azure SQL managed instance named SQL1. You need to ensure that VM1 can access SQL1. Which three components should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. a subnet Correct Answer
  2. a network security perimeter
  3. a virtual network gateway
  4. a network security group (NSG) Correct Answer
  5. a route table Correct Answer

Community Votes

ADE
100%

100% of anonymous learners picked answer ADE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

SQL Managed Instance networking has three mandatory building blocks: a delegated subnet, an NSG on that subnet, and a route table on that subnet. A VNet gateway and network security perimeter are not required for basic VM-to-MI connectivity.

An Azure SQL Managed Instance requires its own dedicated subnet delegated to Microsoft.Sql/managedInstances. That subnet must have a network security group to filter traffic and a user-defined route table to direct traffic (including the route to the managed instance's private endpoint), so VM1 on the same VNet can connect.

Candidates add a VNet gateway or network security perimeter, but those are not part of the core SQL MI subnet requirements; the three required components are the subnet, NSG, and route table.

Community Discussion (4 comments)

husam421 👍 7 Selected: ADE
Dedicated subnet: The subnet SQL Managed Instance can be delegated only to the SQL Managed Instance service. Network security group: A network security group must be associated with the SQL Managed Instance subnet. Route table: A route table must be associated with the SQL Managed Instance subnet.
flmailla 👍 6 Selected: ADE
Answers are correct: https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/connectivity-architecture-overview?view=azuresql&tabs=current#network-requirements
golitech 👍 1 Selected: ADE
Key Requirements for Azure SQL Managed Instance: Dedicated Subnet: Azure SQL Managed Instance requires its own dedicated subnet within the same virtual network as VM1. This subnet must be configured with delegation to "Microsoft.Sql/managedInstances". ✅ Correct Choice: A. a subnet Network Security Group (NSG) for Access Control: NSGs can be used to control traffic between VM1 and SQL1. You must allow inbound/outbound traffic on the required ports (e.g., port 1433 for SQL access). ✅ Correct Choice: D. a network security group (NSG) Route Table to Ensure Proper Routing: SQL Managed Instance uses forced tunneling, and custom route tables may be required to ensure traffic flows correctly between VM1 and SQL1. ✅ Correct Choice: E. a route table
ezmoney 👍 1
Correct Answers (A, D, E) A. a subnet: Create a dedicated subnet for SQL1. D. a network security group (NSG): Control traffic to the subnet where SQL1 is deployed. E. a route table: Ensure proper routing between VM1 and SQL1. These components will enable secure access from VM1 to SQL1.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure SQL Managed Instance must be deployed into a dedicated subnet delegated to the SQL Managed Instance service. Microsoft's connectivity architecture requires that subnet to have an associated network security group (to control traffic) and an associated route table (to route traffic, including the mandatory route to the managed instance). Together with VM1 on the same VNet, these three components enable access. (Options A, D, E)

Why the Other Options Are Wrong

  • Option B (Network security perimeter) is a newer boundary control not required for the basic VM-to-MI connectivity described.
  • Option C (Virtual network gateway) is needed only for on-premises/VPN cross-connectivity, not for VM1 (already in the VNet) to reach the managed instance.

Community Comment Notes

Comments confirmed A, D, E and cited the SQL MI connectivity-architecture-overview article: a dedicated delegated subnet, an NSG, and a route table are all required on the managed instance subnet.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide