QuestionQ55

Network security

Server A (10.2.3.9) must access Server B (10.2.2.7) inside the cloud environment because they are separated into different network sections. All external inbound traffic to these servers must be blocked. Which of the following must be configured to properly secure the cloud network?

Choose two
Explanation

A network security group must explicitly allow traffic from Server A (10.2.3.9) to Server B (10.2.2.7) so the required cross-segment communication can occur. A network security group deny rule from 0.0.0.0/0 to 10.2.0.0/16 blocks inbound traffic originating from external addresses; the specific required allow rule must have higher precedence than the broad deny rule.

Community Discussion

No comments yet. Be the first to start the discussion!