Implement and manage network security groups (NSGs) and application security groups (ASGs) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for Azure network services
      --> Implement and manage network security groups (NSGs) and application security groups (ASGs)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Network security groups (NSGs) and application security groups (ASGs) are foundational Azure networking features used to control traffic within and between Azure virtual networks.

  • Network security groups provide traffic filtering through inbound and outbound security rules.
  • Application security groups allow administrators to organize virtual machines and network interfaces according to application roles rather than relying on individual IP addresses.

Together, NSGs and ASGs support defense in depth, network segmentation, least-privilege access, and easier security-rule management.

An NSG can be associated with:

  • A subnet
  • A network interface card (NIC)
  • Both a subnet and a NIC

When an NSG is associated with a subnet, its rules apply to the resources in that subnet. When it is associated with a NIC, its rules apply to the traffic for that network interface.


1. Understand Network Security Groups

A network security group is an Azure resource containing security rules that allow or deny network traffic.

Each rule can evaluate traffic based on:

  • Source
  • Source port
  • Destination
  • Destination port
  • Protocol
  • Direction
  • Priority
  • Action

Supported protocols include:

  • TCP
  • UDP
  • Any

The action is either:

  • Allow
  • Deny

For example, an NSG rule could allow HTTPS traffic from the Internet to a web server while denying direct inbound access to the database tier.

Example security rule

PropertyExample
NameAllow-HTTPS
DirectionInbound
Priority100
SourceInternet
Source port*
DestinationWeb server subnet
Destination port443
ProtocolTCP
ActionAllow

A lower priority number has higher precedence. For example, priority 100 is evaluated before priority 200.


2. NSG Default Rules

Every NSG contains default security rules. These rules cannot be deleted, but custom rules can override them by using a higher priority.

Common default inbound rules include:

  • Allow traffic from the VirtualNetwork service tag
  • Allow traffic from the AzureLoadBalancer service tag
  • Deny all other inbound traffic

Common default outbound rules include:

  • Allow traffic to the VirtualNetwork service tag
  • Allow traffic to the Internet
  • Deny all other outbound traffic

The default rules are evaluated after custom rules. Therefore, a custom rule with a priority lower than the default deny rule can allow traffic that would otherwise be denied.

Important exam point

NSGs are not automatically “deny all” in every direction. They include default rules that permit certain virtual-network and outbound Internet traffic. Security administrators should explicitly review and override these defaults when stricter controls are required.


3. Inbound and Outbound Rule Evaluation

NSGs filter both inbound and outbound traffic.

Inbound traffic

For a virtual machine with NSGs at both the subnet and NIC levels:

  1. Azure evaluates the subnet-level NSG.
  2. Azure evaluates the NIC-level NSG.
  3. Traffic must be allowed by both NSGs.

Outbound traffic

For outbound traffic:

  1. Azure evaluates the NIC-level NSG.
  2. Azure evaluates the subnet-level NSG.
  3. Traffic must be allowed by both NSGs.

The effective result is the combined set of applicable rules. A deny rule in either NSG can prevent traffic from flowing.

Example

Suppose:

  • The subnet NSG allows inbound TCP 443.
  • The NIC NSG denies inbound TCP 443.

The traffic is denied because both NSGs must permit the traffic.

Similarly:

  • The subnet NSG allows outbound TCP 1433.
  • The NIC NSG denies outbound TCP 1433.

The connection is denied.


4. NSG Rule Priority

Each custom NSG rule must have a unique priority number.

  • Lower numbers have higher priority.
  • Rules are evaluated in priority order.
  • Evaluation stops when a matching rule is found.
  • A later rule cannot override an earlier matching rule.

Example

PriorityRuleAction
100Allow TCP 443 from InternetAllow
110Deny all inbound trafficDeny

HTTPS traffic is allowed because the priority 100 rule is evaluated first.

If the rules were reversed:

PriorityRuleAction
100Deny all inbound trafficDeny
110Allow TCP 443 from InternetAllow

The HTTPS allow rule would never be reached for matching traffic.

Best practices

  • Reserve priority ranges for different application tiers.
  • Use descriptive rule names.
  • Avoid overlapping rules.
  • Place specific rules before broad rules.
  • Avoid using unnecessarily permissive rules such as Any for both source and destination.
  • Document why each rule exists.

5. Source and Destination Options

NSG rules can use several types of source and destination values.

Any

Matches all addresses.

Use this only when broad access is intentionally required.

IP addresses or CIDR ranges

You can specify:

  • A single IP address
  • Multiple IP addresses
  • A subnet range
  • Multiple CIDR ranges

Example:

10.10.1.0/24

Service tags

A service tag represents a group of IP address prefixes associated with an Azure service or category of traffic.

Examples include:

  • VirtualNetwork
  • Internet
  • AzureLoadBalancer
  • AzureCloud
  • Storage
  • AzureKeyVault

Microsoft maintains the IP prefixes represented by service tags and updates them as Azure addresses change. This avoids manually maintaining large lists of IP addresses.

Application security groups

An ASG can be used as the source or destination of an NSG rule. This allows rules to be based on application roles instead of IP addresses.

For example:

Source ASG: Asg-Web
Destination ASG: Asg-Database
Destination port: 1433
Protocol: TCP
Action: Allow

This rule allows members of the web application group to communicate with members of the database group over TCP port 1433.


6. Network Security Group Association

An NSG can be associated with a subnet, a NIC, or both.

Subnet-level association

A subnet-level NSG is useful when a common policy should apply to all resources in the subnet.

Examples:

  • Deny inbound Internet traffic to a private application subnet.
  • Allow communication from a shared management subnet.
  • Restrict outbound traffic from a database subnet.

NIC-level association

A NIC-level NSG is useful when a particular virtual machine requires additional controls beyond the subnet policy.

Examples:

  • A management server requires SSH access.
  • A specific application server needs an additional inbound port.
  • A sensitive VM requires stricter outbound restrictions.

Recommended design

Use subnet-level NSGs for broad segmentation and NIC-level NSGs for workload-specific restrictions. Avoid creating unnecessarily complicated combinations that are difficult to troubleshoot.


7. Understand Application Security Groups

An application security group is a logical grouping of network interfaces.

ASGs allow administrators to define security rules according to application architecture, such as:

  • Web servers
  • Application servers
  • Database servers
  • Management servers
  • Monitoring servers

Instead of creating rules based on individual IP addresses, you can create rules based on group membership.

Example application groups

Asg-Web
Asg-App
Asg-Database
Asg-Management

A rule could allow:

Asg-Web → Asg-App → TCP 8080
Asg-App → Asg-Database → TCP 1433
Asg-Management → Asg-Web → TCP 22

This design is easier to maintain when virtual machines are added, removed, or assigned new IP addresses.

ASGs are logical groupings; they do not themselves filter traffic. The filtering is performed by NSG rules that reference the ASGs.


8. ASG Constraints

Important ASG constraints include:

  • An ASG contains network interfaces, not entire virtual machines directly.
  • All NICs in an ASG must be in the same virtual network.
  • An ASG cannot contain NICs from different virtual networks.
  • If an NSG rule uses an ASG as both source and destination, the referenced ASGs must contain NICs in the same virtual network.
  • A NIC can belong to multiple ASGs.
  • An ASG does not automatically grant access; a matching NSG rule is still required.

The location and virtual-network requirements should be considered when designing application groups.


9. ASGs and Dynamic Application Membership

ASGs are especially useful when application membership changes frequently.

For example, an organization may have:

  • Three web servers today
  • Six web servers next month
  • Different private IP addresses after redeployment

If the web server NICs are members of Asg-Web, the NSG rule can remain unchanged as servers are added or removed.

The administrator only needs to update ASG membership.

Benefits

  • Reduces dependence on hard-coded IP addresses
  • Simplifies rule maintenance
  • Supports application-centric segmentation
  • Makes security intent easier to understand
  • Reduces the number of rules required
  • Helps maintain consistent policies during scaling

Microsoft recommends using ASGs and service tags where appropriate to reduce rule complexity.


10. Example Three-Tier Application Design

Consider a three-tier application:

Internet
|
v
Web tier
|
v
Application tier
|
v
Database tier

Create the following ASGs:

  • Asg-Web
  • Asg-App
  • Asg-Database

Then configure NSG rules such as:

PrioritySourceDestinationPortAction
100InternetAsg-Web443Allow
110Asg-WebAsg-App8080Allow
120Asg-AppAsg-Database1433Allow
130Asg-ManagementAsg-Web22Allow
4000AnyAnyAnyDeny

This approach prevents direct Internet access to the application and database tiers.

The database tier does not need to allow traffic from the entire virtual network. It only needs to allow traffic from the application tier on the required port.


11. Service Tags Versus ASGs

Service tags and ASGs solve different problems.

FeatureService tagsApplication security groups
RepresentsAzure service IP ranges or traffic categoriesApplication network interfaces
ExampleStorage, Internet, AzureLoadBalancerAsg-Web, Asg-Database
Main purposeSimplify access to Azure servicesSimplify application segmentation
Managed byMicrosoft-managed IP prefix updatesCustomer-managed membership
Common useAllow traffic from Azure StorageAllow web servers to access database servers

Use service tags when the source or destination is an Azure service or well-defined traffic category. Use ASGs when the source or destination is a group of application workloads.


12. Augmented Security Rules

Augmented security rules allow multiple values to be specified in a single rule.

For example, one rule can contain:

  • Multiple source IP addresses
  • Multiple destination IP addresses
  • Multiple ports
  • Port ranges

This can reduce the number of individual rules required.

Example:

Source ports: *
Destination ports: 80, 443, 8080
Protocol: TCP
Action: Allow

Augmented rules should be used carefully. Combining unrelated access requirements into one rule can make the security policy harder to understand. Where possible, use service tags and ASGs to express the security intent more clearly.


13. Managing NSGs and ASGs

NSGs and ASGs can be managed through:

  • Azure portal
  • Azure PowerShell
  • Azure CLI
  • Azure Resource Manager templates
  • Bicep
  • Terraform

Typical management tasks include:

  1. Create an NSG.
  2. Create an ASG.
  3. Associate the NSG with a subnet or NIC.
  4. Add NICs to the ASG.
  5. Create inbound and outbound rules.
  6. Test connectivity.
  7. Review effective security rules.
  8. Update or remove obsolete rules.

Azure CLI examples

Create an NSG:

az network nsg create \
--resource-group NetworkRG \
--name nsg-web

Create an ASG:

az network asg create \
--resource-group NetworkRG \
--name asg-web \
--location eastus

Create an inbound rule allowing HTTPS to the web ASG:

az network nsg rule create \
--resource-group NetworkRG \
--nsg-name nsg-web \
--name Allow-HTTPS \
--access Allow \
--protocol Tcp \
--direction Inbound \
--priority 100 \
--source-address-prefix Internet \
--source-port-range "*" \
--destination-asgs asg-web \
--destination-port-range 443

The exact command syntax can vary depending on whether the rule references IP addresses, service tags, or ASGs.


14. Troubleshooting NSG Connectivity

When traffic is unexpectedly blocked, review the following:

1. Confirm the destination port

Ensure the application is actually listening on the expected port.

2. Confirm the source address

The source may be:

  • A private IP address
  • A public IP address
  • A load balancer
  • A service tag
  • Another application group

A rule that allows the wrong source range will not match.

3. Check both NSGs

Review:

  • The subnet-level NSG
  • The NIC-level NSG

A deny rule in either NSG can block traffic.

4. Review effective security rules

Effective security rules show the aggregated rules applied to a NIC, including rules from both the subnet and NIC NSGs.

In the Azure portal, effective rules can be viewed from the VM’s networking settings. They can also be retrieved with Azure CLI:

az network nic list-effective-nsg \
--name vm-nic \
--resource-group NetworkRG

This is one of the most important troubleshooting tools for NSG-related connectivity problems.

5. Check rule priority

A broad deny rule with a higher priority can prevent a later allow rule from being evaluated.

6. Check ASG membership

If an NSG rule references an ASG, verify that the destination or source NIC is actually a member of that ASG.

7. Check other networking controls

NSGs are not the only possible cause of blocked traffic. Also consider:

  • Azure Firewall
  • Network virtual appliances
  • Route tables
  • Private endpoints
  • Application Gateway
  • Operating-system firewalls
  • Application configuration
  • Network Watcher connection troubleshooting

15. NSGs Are Not a Replacement for Azure Firewall

NSGs provide basic network traffic filtering at the subnet and NIC levels. They are not a full network firewall solution.

NSGs generally do not provide the same capabilities as Azure Firewall, such as:

  • Centralized stateful inspection
  • Advanced threat intelligence filtering
  • Intrusion detection and prevention
  • Centralized application and network rule processing
  • Advanced logging and security operations integration

A common defense-in-depth architecture uses:

  • NSGs for subnet and workload segmentation
  • Azure Firewall for centralized traffic inspection
  • Application Gateway WAF for web application protection
  • Private Link for private access to PaaS services
  • Microsoft Defender for Cloud for security posture management

16. Best Practices

Use least privilege

Allow only the required:

  • Sources
  • Destinations
  • Ports
  • Protocols
  • Directions

Prefer application-based rules

Use ASGs instead of individual IP addresses when controlling communication between application tiers.

Use service tags appropriately

Use service tags to avoid maintaining changing Azure service IP ranges manually.

Avoid unrestricted access

Avoid rules that allow:

Source: Any
Destination: Any
Port: Any
Protocol: Any
Action: Allow

unless there is a documented and justified requirement.

Separate application tiers

Use different subnets and ASGs for:

  • Web
  • Application
  • Database
  • Management

Review effective rules

Regularly inspect effective security rules to verify that the actual applied policy matches the intended design.

Use infrastructure as code

Define NSGs, ASGs, and rules in Bicep, ARM templates, or another approved infrastructure-as-code solution to improve consistency and auditability.

Remove obsolete rules

Unused rules increase complexity and may create unintended access paths.

Document security intent

Use descriptive names and descriptions such as:

Allow-App-to-Database-SQL

rather than:

Rule1

Practice Exam Questions

Question 1

A company hosts a three-tier application in Azure. Web servers must communicate with application servers over TCP port 8080. Application servers must communicate with database servers over TCP port 1433. The company wants security rules to remain valid when virtual machines are added or their private IP addresses change.

What should you implement?

A. Create ASGs for each application tier and reference them in NSG rules.
B. Create a separate NSG for every virtual machine using static IP addresses.
C. Allow all traffic between the application subnets.
D. Use public IP addresses for all application servers.

Correct answer: A

Explanation: ASGs allow NSG rules to reference application roles instead of individual IP addresses. Membership can change without requiring the security rules to be rewritten.


Question 2

An NSG associated with a subnet allows inbound TCP port 443. An NSG associated with a VM’s NIC denies inbound TCP port 443 from the same source.

What is the result?

A. The subnet NSG takes precedence, so traffic is allowed.
B. The NIC NSG takes precedence, so traffic is denied.
C. Azure randomly selects one of the rules.
D. The traffic is allowed only if the VM has a public IP address.

Correct answer: B

Explanation: Both the subnet-level and NIC-level NSGs apply. Traffic must be allowed by both. The deny rule in the NIC-level NSG blocks the connection.


Question 3

An administrator creates an NSG rule with priority 100 that denies all inbound traffic. Another rule with priority 200 allows inbound HTTPS traffic.

What happens to inbound HTTPS traffic?

A. HTTPS is allowed because it uses a secure protocol.
B. HTTPS is allowed because the allow rule is more specific.
C. HTTPS is denied because the priority 100 rule is evaluated first.
D. Azure combines the actions and allows the traffic.

Correct answer: C

Explanation: Lower priority numbers are evaluated first. The broad deny rule at priority 100 matches the traffic, so the later allow rule is not evaluated.


Question 4

A VM cannot receive traffic from another VM in the same virtual network. The NSG associated with the destination NIC allows the traffic, but the subnet-level NSG contains a deny rule.

What should the administrator do first?

A. Assign a public IP address to the destination VM.
B. Review and modify the subnet-level NSG rule.
C. Disable the destination VM’s operating-system firewall.
D. Create an Azure Firewall policy.

Correct answer: B

Explanation: Both the subnet-level and NIC-level NSGs apply. A deny rule at the subnet level can block traffic even when the NIC-level NSG allows it.


Question 5

An organization wants to allow traffic from Azure Storage without manually maintaining a list of changing Azure IP addresses.

Which feature should be used?

A. Application security group
B. User-defined route
C. Service tag
D. Public IP prefix

Correct answer: C

Explanation: Service tags represent Microsoft-managed groups of IP address prefixes for Azure services. Microsoft updates the prefixes as service addresses change.


Question 6

A security administrator creates an ASG named Asg-Database. The administrator then creates an NSG rule allowing traffic to Asg-Database on TCP port 1433.

A database VM is not receiving the traffic.

Which issue could explain the problem?

A. The VM’s NIC is not a member of Asg-Database.
B. ASGs automatically deny all traffic.
C. ASGs can contain only public IP addresses.
D. ASGs work only with Azure Firewall.

Correct answer: A

Explanation: An NSG rule referencing an ASG applies only to network interfaces that are members of that ASG. The ASG itself does not automatically include every VM in a subnet.


Question 7

Which statement about application security groups is correct?

A. An ASG directly filters traffic without an NSG.
B. An ASG can contain NICs from multiple virtual networks.
C. An ASG is a logical grouping of network interfaces used by NSG rules.
D. An ASG replaces the need for subnet-level NSGs.

Correct answer: C

Explanation: ASGs provide logical grouping. NSG rules perform the actual allow or deny operation. NICs in an ASG must be in the same virtual network.


Question 8

A VM cannot connect to a database server. The administrator wants to see the combined inbound and outbound rules applied from the subnet and NIC NSGs.

Which feature should be used?

A. Azure Advisor
B. Effective security rules
C. Microsoft Defender Vulnerability Management
D. Azure Service Health

Correct answer: B

Explanation: Effective security rules show the aggregated rules applied to a network interface and are designed to help troubleshoot NSG-related connectivity issues.


Question 9

A company wants to allow management traffic only from a management subnet to selected application servers. The application servers are distributed across several subnets in the same virtual network.

What is the most maintainable approach?

A. Add every application server’s private IP address to a separate rule.
B. Allow management traffic from the entire virtual network to every server.
C. Create an ASG for the management servers and an ASG for the target application servers, then reference them in an NSG rule.
D. Assign public IP addresses to the management servers.

Correct answer: C

Explanation: ASGs allow security policies to be expressed according to application roles. The rule can remain stable as servers are added or their IP addresses change.


Question 10

An administrator wants to create a rule that allows TCP ports 80, 443, and 8080 from a specified source range using one NSG rule.

Which NSG capability supports this configuration?

A. Augmented security rules
B. Azure Bastion
C. Application Gateway WAF
D. Private Link

Correct answer: A

Explanation: Augmented security rules allow multiple ports, addresses, and ranges to be specified in a single rule, reducing the number of individual rules required.


Final Exam Point

NSGs and ASGs are most effective when used together: NSGs enforce traffic rules, while ASGs make those rules easier to express and maintain according to application architecture.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply