Answer : B
For this requirement, they need to use Network Security Groups
With Network Security Groups, you can add Inbound rules to restrict the Inbound traffic to virtual machines. An example snapshot of the Network Security Group rules is given below.
The Azure Security Center service is used to strengthen the security posture of resources created as part of your Azure subscription.
For more information on the Azure Network Security Groups, please visit the below URL
https://docs.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview