Which two Azure resources can a network security group (NSG) be associated with?

Disable ads (and more) with a membership for a one time $4.99 payment

Study for the Microsoft SC-900 Exam. Master key concepts with targeted flashcards and multiple-choice questions, featuring hints and explanations. Get prepared and confident for success!

A network security group (NSG) can be associated with both a virtual network subnet and a network interface. Associating an NSG with a virtual network subnet allows you to apply the same security rules to all the network interfaces attached to the resources within that subnet, providing a centralized way to manage security across multiple resources.

When an NSG is linked to a network interface, it directly manages the inbound and outbound traffic for that specific interface. This granularity is essential for securing your resources based on their specific roles or traffic requirements.

The other resources mentioned, such as a resource group, a virtual network, and an Azure App Service web app, do not directly support the association of NSGs in the same manner. Resource groups are organizational containers, and while a virtual network does encompass subnets, the NSG needs to be tied specifically to either a subnet or a network interface to be effective. Azure App Services typically rely on different security mechanisms such as firewalls and service endpoints rather than NSGs for controlling traffic.