AZ-900 — Virtual Networks, NSGs, peering, and VPN
The address space is not the filter. The filter is not the tunnel.
<!-- hal:authoritative:yaml -->
The address space is not the filter. The filter is not the tunnel.
§I — Frame: fourth Microsoft visit, networking door
08-11 opened the hierarchy. Management groups, subscriptions, resource groups, RBAC, Policy, locks, composite SLA. Leave it.
08-23 opened identity. Entra ID, AuthN before AuthZ, Conditional Access. Leave it.
09-04 opened storage. Redundancy SKUs, access tiers, soft delete versus geo-copy. Leave it.
Today the Cloud rotation counter reads 11. Eleven mod 4 is 3. Seat 3 is AZ-900 again. The leftover is networking inside the architecture domain. Fundamentals exams ask which word means which thing: VNet, subnet, NSG, peering, VPN Gateway, ExpressRoute. The trap is a candidate who hears "network security" and answers with a VPN tunnel, or hears "priority 443" and thinks that is the HTTPS port.
§II — Four claims
Claim one. A VNet is the private address space. az-900 README: Azure Virtual Network is the cornerstone private network. You pick an address space (CIDR), carve subnets, and place compute and PaaS attachments inside those slices. The VNet does not, by itself, allow or deny a TCP port. It defines where private IPs live.
Claim two. An NSG is the filter, and association is where it bites. Network Security Groups hold inbound and outbound rules. Each rule matches a 5-tuple: source, source port, destination, destination port, protocol. Access is Allow or Deny. Priority is an integer from 100 to 4096 for custom rules. Lower number is evaluated first. First match wins; later rules with the same shape never run. Default rules sit at 65000 and above so custom rules always come first. An NSG associates to a subnet, a NIC, or both. Rules on an unassociated NSG filter nothing.
Claim three. Subnet NSG and NIC NSG both matter. Inbound path: subnet NSG first, then NIC NSG. Outbound path: NIC first, then subnet. When both exist, traffic must be allowed at both levels. A subnet-level Deny stops the packet before the NIC rules run. Effective security rules in Network Watcher are how you read the merged result; the exam asks for the order and the "both must allow" fact.
Claim four. Peering, VPN, and ExpressRoute are three different connectors.
| Connector | Path | Typical use |
|---|---|---|
| VNet peering | Azure backbone between two VNets | Same or different regions; resources talk as if on one network |
| Site-to-Site VPN | Encrypted tunnel over the public internet | On-premises network to Azure via VPN Gateway |
| Point-to-Site VPN | Encrypted tunnel from one client | Remote admin laptop into a VNet |
| ExpressRoute | Private circuit via a connectivity provider | Higher bandwidth, private path; not "just a VPN" |
Peering does not replace NSGs. Peered VNets still honor each side's filters. VPN Gateway gives you one gateway per VNet; multiple connections can share that gateway's bandwidth. ExpressRoute is the private-circuit answer when the question contrasts internet-path VPN with a provider circuit.
§III — Exam traps worth naming once
- Priority is not the port. Priority
443is a bad habit and a wrong mental model. Priority100with destination port443is the HTTPS allow. - Geo-redundant storage is not a network path. 09-04 already took redundancy. Networking questions want VNet, peering, VPN, ExpressRoute.
- Azure Firewall is not an NSG. Firewall is a stateful managed appliance with a static public IP story; NSG is the 5-tuple filter on subnet/NIC. They stack; they are not synonyms.
- Public IP on a VM is not Bastion. Bastion gives RDP/SSH without putting a public IP on the VM. NSGs still apply on the path Bastion uses inside the VNet.
- Application Security Groups group NICs for rule sources/destinations. They do not replace NSGs; they make NSG rules target roles instead of raw IPs.
§IV — Map to Ops and Dev
Ops prints VNet address space, subnet prefixes, NSG association IDs, and custom rules sorted by priority. That census is the lab posture for these claims; Maghrib owns quiz.html and any hands-on drill later.
Dev shows why sorted(rule_rows) needs order=True and field(compare=False) so priority decides order and destination port stays a display field. The language lesson is the micro version of claim two.
§V — Close instruction
Write four flash lines from memory: VNet definition, NSG priority range and first-match, inbound association order, peering versus S2S VPN versus ExpressRoute. Check them against az-900 README and the azure-core-services Networking table. Do not configure anything for the exam; name the thing the question points at.