A review classifies each control by the defence-in-depth layer it operates at. Where does a network security group blocking traffic between the application subnet and the database subnet belong, and what does that layer contribute?
Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Correct The network layer: it limits lateral movement by controlling which traffic may pass between segments, so a compromised web tier cannot simply reach the database
Correct. Segmentation is the network layer's contribution, and containing lateral movement is precisely what it buys once something inside has been compromised.
Not correct The identity and access layer, because it decides who is allowed to connect
Wrong. A network security group matches addresses, ports and protocols. It has no idea which user is behind a packet — that judgement belongs to identity controls.
Not correct The perimeter layer, because it is a firewall of sorts
Wrong. The perimeter layer concerns the edge of the estate — absorbing volumetric attacks and filtering what arrives from outside. This rule governs traffic already inside, between two internal segments.
Not correct The data layer, because a database sits behind it
Wrong. The data layer is about protecting the data itself: encryption at rest and in transit, and control of the keys. A control's layer is decided by what the control does, not by what happens to be behind it.
Why
Classify a control by the mechanism it uses, not by the asset it happens to sit in front of. Address-and-port rules between segments are network layer. Sign-in requirements and role assignments are identity and access. Volumetric protection at the edge is perimeter. Patching and endpoint protection are compute. Encryption and key control are data. The same database can be protected at four different layers, and in a healthy design it is.
Where this comes from
- Cited
- Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security
Practise this
Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.
Practise Microsoft Certified: Azure Fundamentals (AZ-900)
More questions on this objective
- An image-resizing routine runs for about two seconds whenever a file lands in a storage container — perhaps two hundred times on a busy day, and not at all on a quiet one. The team wants to pay for the work done and maintain no servers. Which compute option fits? machine-checked
- A fifteen-year-old accounting application needs a kernel-level driver, a scheduled task that edits the registry, and a runtime version nobody supports any more. The business wants it running in Azure this quarter with as few code changes as possible. Where does it go? machine-checked
- A team runs nine small services, each with its own conflicting library versions. They want each one packaged with its dependencies, starting in seconds, several to a host, without a separate operating system per service. Which compute type are they describing? machine-checked
- Which TWO of these statements about Azure compute types are true? machine-checked
- A public website runs on four identical virtual machines behind a load balancer. Traffic triples while a television advert airs and falls back an hour later. The team wants instances added and removed automatically against CPU, all built from one image, with nobody clicking. Which option is designed for that? machine-checked
- Three virtual machines form a quorum-based cluster in a region that has no availability zones. You want them placed so that neither a single rack losing power nor a single batch of planned host maintenance can take all three at once. What do you configure? machine-checked