AZ-400 – Question 121


You need to prepare a network security group (NSG) named az400-9940427-nsg1 to host an Azure DevOps pipeline agent. The solution must allow only the required outbound port for Azure DevOps and deny all other inbound and outbound access to the Internet.
To complete this task, sign in to the Microsoft Azure portal.

Correct Answer: See explanation below.

Here is what Azure DevOps Server is:

Developers can work in the cloud using Azure DevOps Services or on-premises using Azure DevOps Server. Azure DevOps Server was formerly named Visual Studio Team Foundation Server (TFS).

But we’ve asked to deny everything else, one this is done we have to open for the RDP or SSH port to connect in order to install the agent.

So for me:
Inbound :
100 RDP/SSH 3389/22 Allow
110 * Deny
100 * 443 Allow

110 * Deny