Q: 3
Your company plans to move several servers to Azure. The company's compliance policy states that a server named FinServer must be on a separate network segment You are evaluating which Azure services can be used to meet the compliance policy requirements. Which Azure solution should you recommend?
Options
Discussion
B tbh. Only a separate VNet (option B) actually creates a distinct network segment for FinServer like the compliance policy asks. Resource groups (A or D) are more about management boundaries, not actual network segmentation, so they're a bit of a trap here. Pretty sure this is what AZ-900 wants, but happy to hear other angles if I've missed some Azure nuance.
A or D, since resource groups seem like they give separation too, right?
A tbh, had something like this in a mock and resource groups were picked for segmenting compliance workloads.
Probably B. Only virtual networks in Azure give you true network-level isolation, which the compliance policy wants for FinServer. Resource groups are just for management, not segmentation. I think B fits best but happy to hear other views.
B tbh, but if FinServer needed to talk privately with the others via peering, that would start breaking strict segment separation. That nuance tripped folks in some similar exam reports. Check if the policy is about total isolation or just different subnets.
B , resource groups (A/D) are a trap since they don't control network segmentation at all.
Its B. Resource groups just help with organizing, not actual network isolation. Separate VNets give you that real network segment separation for compliance, at least from what I understand. Not 100% if there's a weird Azure exception though.
Had something like this in a mock. Picking B since only a separate VNet actually isolates FinServer at the network level, which is what the policy wants. Resource groups (A) don’t give true network segmentation. Someone correct me if there’s a nuance I’m missing but pretty sure it’s B.
B Saw a similar question on an official practice test and it wanted separate VNets for real isolation. Official study guide explains this topic pretty clear too.
Its A. Resource groups can enforce logical separation, which some consider enough for compliance (trap is thinking only VNets count).
Be respectful. No spam.