Your on-premises network contains a database server and is accessible by using a VPN server.
You have a Microsoft 365 tenant.
You manage devices by using Microsoft Endpoint Manager.
You have an application named App1 that is deployed to every computer enrolled in Microsoft Intune. Each computer has a VPN profile assigned.
You need to ensure that App1 can access only the database server. App1 must be prevented from accessing other resources on the on-premises network.
What should you modify in the VPN profile?
Correct Answer: B
Explanation
You can use an Azure network security group to filter network traffic to and from Azure resources in an Azure virtual network. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources. For each rule, you can specify source and destination, port, and protocol.
A network security group contains zero, or as many rules as desired, within Azure subscription limits.
Reference: https://docs.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview