Answer : A
Explanation :
It would help if you used network security groups to allow or deny traffic within subnets.
Below is what the Microsoft documentation mentions in terms of filtering network traffic.
Filtering Network traffic in Microsoft Azure
Option B is incorrect since this is used as a messaging system.
Option C is incorrect since this is used to represent a VPN device in a Site-to-Site VPN connection.
Option D is incorrect since this is normally used to connect networks via the Internet.