Minimum Application Security Groups for Peered VNets
You have two Azure virtual networks named VNet1 and VNet2 that are peered with each other. VNet1 hosts 10 virtual machines that contain web servers. VNet2 hosts five virtual machines that contain database servers. You need to configure a security solution that meets the following requirements: • Ensures that the database servers can accept connections only from the web servers • Ensures that the web servers can initiate connections only to the database servers • Ensures that all network security groups (NSGs) are associated only with subnets • Use application security groups to implement the solution What is the minimum number of application security groups required?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of ASG scope and granularity; the trap is over-associating NSGs with NICs instead of subnets or creating redundant groups when a single group can represent all instances of a role.
Determines the minimum number of Application Security Groups (ASGs) needed to secure traffic between web and database servers in peered Azure VNets. Establishes that two ASGs are required, one per server role.
Learners often choose 4 by assuming separate groups are needed for each VNet or direction, but an ASG is a logical grouping of VMs regardless of VNet, so one group suffices per role type.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To meet the requirements using Application Security Groups (ASGs), you need to group the virtual machines by their functional role rather than their network location. You create one ASG for the 'Web Servers' (containing the 10 VMs from VNet1) and a second ASG for the 'Database Servers' (containing the 5 VMs from VNet2). This totals 2 ASGs. The NSGs associated with the subnets use these ASGs as source/destination addresses in their rules: allowing traffic from the Web ASG to the DB ASG on port 3389/1433/etc., and denying all other traffic. This satisfies the bidirectional constraint and keeps NSGs associated only with subnets.Why the Other Options Are Wrong
Option A (1) is incorrect because a single ASG cannot distinguish between source and destination roles in the same way; if both web and db were in one group, the NSG rule would be ambiguous or allow unrestricted internal communication within that group. Option C (4) and D (8) suggest unnecessary complexity, such as creating separate groups per VNet or per direction, which violates the principle of minimizing resources while meeting security goals. ASGs are not limited to a single VNet; they can span multiple VNets if needed, but here we just need role-based separation.Community Comment Notes
Community consensus strongly supports answer B. Users like Saba53 note that one ASG covers all web servers and another covers all database servers. Abilash2605 mentions the restriction logic, though technically ASGs aren't strictly restricted to one VNet, the conclusion holds for this scenario. Bobothewiseman simply confirms the count of 2.Exam Strategy
When asked for the minimum number of security groups, always look for the smallest logical unit that defines the security policy. Group by function (e.g., Web, DB, App) rather than by infrastructure topology unless the policy explicitly requires it.
Frequently Asked Questions
Can an ASG contain VMs from different VNets?
Yes, an ASG is a logical grouping that can include VMs from any VNet in the same subscription or via peering, provided they are in the same tenant.
Why not use 1 ASG for everything?
A single ASG cannot enforce directional restrictions between its members easily. Separate groups allow precise NSG rules defining who can talk to whom.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →