Example would be something like securing a domain controller so that clients can only access the required ports for AD functionality.
Currently I have to create at least 9 rules for TCP, another 4 for UDP.
With Network Port groups, this would be a single rule, maybe 2 if not mixing TCP and UDP ports.
This would allow for much less ACLs in the firewall rules table, which will be better for troubleshooting and system memory usage.