New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AZ-700 Exam - Topic 4 Question 77 Discussion

Actual exam question for Microsoft's AZ-700 exam
Question #: 77
Topic #: 4
[All AZ-700 Questions]

You have an Azure subscription that contains a virtual machine named VM1 and a network security group (NSG) named NSG1. NSG1 has the default rules configured VM1 runs Windows Server and contains a single NIC named NIC1 NIC! is associated with NSG1.

You need to prevent access to the Azure Instance Metadata Service (IMDS) REST API on VM1 The solution must minimize administrative effort.

What should you add to NSG1?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

0/2000 characters
Deeanna
3 months ago
C seems overkill for just blocking IMDS access.
upvoted 0 times
...
Tom
3 months ago
Wait, can you really block IMDS like that? Sounds tricky.
upvoted 0 times
...
Hester
3 months ago
I think A might work too, but it feels less efficient.
upvoted 0 times
...
Ashley
4 months ago
Definitely B, service tags are the way to go!
upvoted 0 times
...
Allene
4 months ago
You need to block access to the IMDS API.
upvoted 0 times
...
Percy
4 months ago
I’m a bit confused about whether I should focus on inbound or outbound rules here. I thought inbound rules were more about preventing access from outside, but this seems different.
upvoted 0 times
...
Rebbecca
4 months ago
I feel like we practiced a similar question where we had to block access to a specific service. I think an outbound rule is what we used then.
upvoted 0 times
...
Dallas
4 months ago
I'm not entirely sure, but I think using a service tag could simplify things. It might be a good option to minimize admin effort.
upvoted 0 times
...
Boris
5 months ago
I remember we discussed how the Azure Instance Metadata Service has a specific IP address, so blocking outbound traffic to that IP might be the way to go.
upvoted 0 times
...
Annette
5 months ago
I'm a little confused here. Wouldn't blocking traffic to an IP address or application security group be more specific and targeted than using a service tag? I'm not sure if that would be considered "minimizing administrative effort" compared to the other options.
upvoted 0 times
...
Lavonda
5 months ago
Okay, let me think this through. We need to prevent access to the IMDS REST API, and the question says the solution should minimize administrative effort. I'm thinking option B, the outbound rule blocking a service tag, might be the way to go. It seems like the most straightforward approach.
upvoted 0 times
...
Darrel
5 months ago
Hmm, I'm a bit unsure about this one. Blocking traffic to an IP address or application security group seems like it might require more manual configuration. I'm wondering if the service tag approach in option B could be the simplest solution.
upvoted 0 times
...
Adria
5 months ago
I think the key here is to block access to the IMDS REST API on VM1. Based on the question, the solution should minimize administrative effort, so I'm leaning towards option B - adding an outbound rule that blocks traffic to a service tag.
upvoted 0 times
...
Lashon
9 months ago
Forget all this networking stuff, I'm just going to use the IMDS API to order some tacos. What could go wrong?
upvoted 0 times
...
Margret
9 months ago
Ha! I bet the exam writers are trying to trip us up with these options. Let's see, B seems like the winner to me.
upvoted 0 times
Isaiah
8 months ago
User4: Let's go with B then. It seems like the most logical choice.
upvoted 0 times
...
Alonso
8 months ago
User3: I'm not so sure, but I'll go with B too.
upvoted 0 times
...
Jeanice
9 months ago
User2: Yeah, I agree. B sounds like the right choice.
upvoted 0 times
...
Chandra
9 months ago
User1: I think B is the best option.
upvoted 0 times
...
...
Corrina
10 months ago
This is a tricky one. I was considering C, but I'm not sure if adding both inbound and outbound rules is really necessary to achieve the desired outcome.
upvoted 0 times
Elke
8 months ago
User3: I'm not sure, but I think D is the right choice as well. Let's go with that.
upvoted 0 times
...
Shaun
8 months ago
User2: I agree with User1. D seems like the most straightforward solution.
upvoted 0 times
...
Carlene
9 months ago
User1: I think D is the correct option. Just block traffic to the IP address.
upvoted 0 times
...
...
Eden
10 months ago
I'm not sure about this one. Wouldn't an inbound rule that blocks traffic to an IP address (D) be a more targeted solution?
upvoted 0 times
Lonny
9 months ago
User1: Maybe we should consider both options and see which one works best for our scenario.
upvoted 0 times
...
Rebeca
9 months ago
User2: I disagree, I believe an inbound rule that blocks traffic to an IP address (D) would be more effective.
upvoted 0 times
...
Shalon
9 months ago
User1: I think an outbound rule that blocks traffic to an IP address (A) would be the best option.
upvoted 0 times
...
...
Felicitas
10 months ago
Hmm, I think B is the correct answer. Blocking traffic to the IMDS service tag seems like the most straightforward way to prevent access to the IMDS REST API.
upvoted 0 times
Ammie
8 months ago
User4: Let's go with option B then.
upvoted 0 times
...
Della
9 months ago
User3: That sounds like the most straightforward way to prevent access to the IMDS REST API.
upvoted 0 times
...
Alverta
9 months ago
User2: I agree, blocking traffic to the IMDS service tag makes sense.
upvoted 0 times
...
Tomas
9 months ago
User1: I think B is the correct answer.
upvoted 0 times
...
...
Noah
11 months ago
I'm not sure. Wouldn't it be better to add an inbound rule that blocks traffic to an IP address instead?
upvoted 0 times
...
Julie
11 months ago
I agree with Melodie. Blocking traffic to a specific IP address seems like the most straightforward solution.
upvoted 0 times
...
Melodie
11 months ago
I think we should add an outbound rule that blocks traffic to an IP address.
upvoted 0 times
...

Save Cancel