A review classifies each control by the defence-in-depth layer it operates at. Where does a network security group blocking traffic between the application subnet and the database subnet belong, and what does that layer contribute?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct The network layer: it limits lateral movement by controlling which traffic may pass between segments, so a compromised web tier cannot simply reach the database

Correct. Segmentation is the network layer's contribution, and containing lateral movement is precisely what it buys once something inside has been compromised.

Not correct The identity and access layer, because it decides who is allowed to connect

Wrong. A network security group matches addresses, ports and protocols. It has no idea which user is behind a packet — that judgement belongs to identity controls.

Not correct The perimeter layer, because it is a firewall of sorts

Wrong. The perimeter layer concerns the edge of the estate — absorbing volumetric attacks and filtering what arrives from outside. This rule governs traffic already inside, between two internal segments.

Not correct The data layer, because a database sits behind it

Wrong. The data layer is about protecting the data itself: encryption at rest and in transit, and control of the keys. A control's layer is decided by what the control does, not by what happens to be behind it.

Why

Classify a control by the mechanism it uses, not by the asset it happens to sit in front of. Address-and-port rules between segments are network layer. Sign-in requirements and role assignments are identity and access. Volumetric protection at the edge is perimeter. Patching and endpoint protection are compute. Encryption and key control are data. The same database can be protected at four different layers, and in a healthy design it is.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services