Production lock VNets across three subscriptions must share one network security baseline, while a sandbox VNet must stay out. Where should the security engineer apply the Azure Virtual Network Manager security admin configuration?
Select an answer to reveal the explanation.
Short Explanation
Herd the production lock VNets into an AVNM network group, hang the security admin config on that group, and leave the sandbox cow outside the fence.
Full Explanation
Azure Virtual Network Manager targets security admin and connectivity configurations at network groups, which can use static or conditional membership across subscriptions. Production VNets belong in the group that receives the baseline; the sandbox VNet is omitted. Management-group Azure Policy assignment is a different control plane and is not the AVNM network-enforcement target. Flow-log queries observe traffic; they do not enforce admin rules.