What essential networking mechanisms define an Azure Subnet when segmenting a Virtual Network into isolated, high-security IP address spaces for enterprise workloads? Furthermore, why is applying precise Network Security Group policies at the subnet level the absolute most effective strategy for managing cloud traffic isolation and zero-trust security?