AZ-305 exam dumps

AZ-305 practice question 237 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 237

Single answer

You are designing the network architecture for a multi-tier web application hosted in Azure. The solution must centrally log all inbound and outbound traffic, provide advanced threat detection capabilities, and enforce micro-segmentation between the front-end and back-end tiers. You also need to restrict which external services the application servers can reach on the internet while allowing secure inbound access to the web tier. Which solution best satisfies these requirements?

  1. A

    Use only Network Security Groups (NSGs) attached to each subnet to filter and log all inbound and outbound traffic.

  2. B

    Implement an Application Gateway WAF for inbound traffic and rely on default outbound internet rules without additional controls.

  3. C

    Deploy Azure Firewall with threat intelligence-based filtering and DNAT rules for inbound traffic, combined with NSGs for micro-segmentation between tiers.

  4. D

    Enable Azure DDoS Protection Standard and rely on on-premises firewalls for traffic filtering and logging.

Show answer and explanation

Correct answer: C

Explanation

Using Azure Firewall with threat intelligence-based filtering and DNAT for inbound traffic, plus NSGs for micro-segmentation, is a common Azure best practice. Azure Firewall supports logging all events to Azure Monitor, integrates with Azure Sentinel for threat analysis, and enforces outbound filters. NSGs further restrict traffic between tiers, completing the defense-in-depth approach. Refer to the Azure Firewall documentation (https://learn.microsoft.com/azure/firewall/) and the NSG best practices (https://learn.microsoft.com/azure/virtual-network/network-security-group-howitworks) for detailed implementation guidance.

  • A. Incorrect.

    Option 1: Network Security Groups can control inbound and outbound traffic at the subnet or NIC level, but they do not provide advanced threat intelligence or centralized logging. NSGs alone lack features like DNS-based filtering and comprehensive logging with advanced analytics.

  • B. Incorrect.

    Option 2: Application Gateway WAF protects web applications from common exploits and attacks but does not handle outbound traffic restrictions or advanced threat intelligence filtering for non-HTTP/S traffic. Relying solely on default outbound internet rules leaves other protocols and destinations unmonitored.

  • C. Correct.

    Option 3: Azure Firewall can enforce outbound traffic restrictions, provide advanced threat intelligence-based filtering, and support inbound DNAT rules. Coupling Azure Firewall with NSGs for micro-segmentation ensures that each application tier is appropriately isolated. This combination meets the requirements for inbound protection, outbound restrictions, centralized logging, and micro-segmentation.

  • D. Incorrect.

    Option 4: Azure DDoS Protection Standard helps mitigate distributed denial of service attacks but does not offer the detailed traffic filtering or logging required here. Relying solely on on-premises firewalls for Azure traffic limits visibility and management capabilities in the cloud.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam