A canal authority wants FQDN filtering, threat-intelligence-based deny, and SNAT for many spokes. A contractor proposes adding more NSG rules. What should the security engineer choose?
Select an answer to reveal the explanation.
Short Explanation
NSGs are great at five-tuple stop signs—not FQDN sniffing, threat intel, or hub SNAT. Park Azure Firewall (or a secured hub) in the middle and leave NSGs on the curb.
Full Explanation
Network Security Groups enforce allow/deny on five-tuple criteria at subnet or NIC scope. They do not provide FQDN filtering, Microsoft threat-intelligence deny lists, or centralized SNAT for many spokes. Azure Firewall—standalone or in a secured virtual hub—covers those requirements while NSGs continue to harden individual subnets and NICs. Secure Score and VNet address planning are not substitutes for that control selection.