Minimum Application Security Groups for Peered VNets

Implement and manage network security groups
Answer Correct answer: B — Two application security groups are required: one for the web servers and one for the database servers.

You have two Azure virtual networks named VNet1 and VNet2 that are peered with each other. VNet1 hosts 10 virtual machines that contain web servers. VNet2 hosts five virtual machines that contain database servers. You need to configure a security solution that meets the following requirements: • Ensures that the database servers can accept connections only from the web servers • Ensures that the web servers can initiate connections only to the database servers • Ensures that all network security groups (NSGs) are associated only with subnets • Use application security groups to implement the solution What is the minimum number of application security groups required?

  1. 1
  2. 2 Correct Answer
  3. 4
  4. 8

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of ASG scope and granularity; the trap is over-associating NSGs with NICs instead of subnets or creating redundant groups when a single group can represent all instances of a role.

Determines the minimum number of Application Security Groups (ASGs) needed to secure traffic between web and database servers in peered Azure VNets. Establishes that two ASGs are required, one per server role.

Learners often choose 4 by assuming separate groups are needed for each VNet or direction, but an ASG is a logical grouping of VMs regardless of VNet, so one group suffices per role type.

Community Discussion (3 comments)

Saba53 👍 1 Selected: B
answer is correct 1 ASG for the web servers: This will include all web servers in VNet1. 1 ASG for the database servers: This will include all database servers in VNet2.
bobothewiseman 👍 1 Selected: B
2 application security group
Abilash2605 👍 1 Selected: B
ASG is restricted one per Vnet. for two Vnets you need two ASGs minimum.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To meet the requirements using Application Security Groups (ASGs), you need to group the virtual machines by their functional role rather than their network location. You create one ASG for the 'Web Servers' (containing the 10 VMs from VNet1) and a second ASG for the 'Database Servers' (containing the 5 VMs from VNet2). This totals 2 ASGs. The NSGs associated with the subnets use these ASGs as source/destination addresses in their rules: allowing traffic from the Web ASG to the DB ASG on port 3389/1433/etc., and denying all other traffic. This satisfies the bidirectional constraint and keeps NSGs associated only with subnets.

Why the Other Options Are Wrong

Option A (1) is incorrect because a single ASG cannot distinguish between source and destination roles in the same way; if both web and db were in one group, the NSG rule would be ambiguous or allow unrestricted internal communication within that group. Option C (4) and D (8) suggest unnecessary complexity, such as creating separate groups per VNet or per direction, which violates the principle of minimizing resources while meeting security goals. ASGs are not limited to a single VNet; they can span multiple VNets if needed, but here we just need role-based separation.

Community Comment Notes

Community consensus strongly supports answer B. Users like Saba53 note that one ASG covers all web servers and another covers all database servers. Abilash2605 mentions the restriction logic, though technically ASGs aren't strictly restricted to one VNet, the conclusion holds for this scenario. Bobothewiseman simply confirms the count of 2.

Exam Strategy

When asked for the minimum number of security groups, always look for the smallest logical unit that defines the security policy. Group by function (e.g., Web, DB, App) rather than by infrastructure topology unless the policy explicitly requires it.

Frequently Asked Questions

Can an ASG contain VMs from different VNets?

Yes, an ASG is a logical grouping that can include VMs from any VNet in the same subscription or via peering, provided they are in the same tenant.

Why not use 1 ASG for everything?

A single ASG cannot enforce directional restrictions between its members easily. Separate groups allow precise NSG rules defining who can talk to whom.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide