AZ-500 exam dumps

AZ-500 practice question 107 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 107

Single answer

You are deploying Azure Front Door to serve static content from an Azure Storage account and dynamic content from an Azure App Service in multiple regions. You want to minimize latency for global users, ensure SSL/TLS encryption end to end, and use a custom domain with your Front Door and CDN configuration. Which of the following configurations should you implement to achieve these goals?

  1. A

    A) Create a custom domain, point it to your Front Door endpoint via a CNAME record, enable Front Door managed certificates for HTTPS, and allow only HTTPS traffic from Azure Front Door on your origin backends.

  2. B

    B) Map your custom domain directly to the Azure Storage account, enable HTTP access only at the CDN level for performance, and forward all traffic through Azure Front Door.

  3. C

    C) Use the default Front Door domain for all requests, install a self-signed certificate on each backend, and keep all inbound protocols open on the origin backends.

  4. D

    D) Configure your custom domain with DNS A records pointing to each backend, then enable partial HTTPS on the origin and HTTP-only from Front Door to reduce certificate overhead.

Show answer and explanation

Correct answer: A

Explanation

Implementing an Azure Front Door with a custom domain and full HTTPS ensures global load balancing, high availability, and secure delivery of content. By using a CNAME record pointing to the Front Door endpoint, enabling HTTPS with a managed certificate, and restricting backend connections to only approved traffic over HTTPS, you follow Azure Front Door best practices. For more information, refer to: https://learn.microsoft.com/azure/frontdoor/.

  • A. Correct.

    Option A is correct. Enabling a custom domain with a CNAME record to the Front Door endpoint, then using Front Door’s managed SSL certificates, ensures secure, end-to-end encryption. Restricting backend access to only HTTPS traffic from Front Door further protects your resources. This follows best practices for global content delivery and security in Azure.

  • B. Incorrect.

    Option B is incorrect. Enabling only HTTP at the CDN level risks exposing sensitive data in transit. Forwarding traffic via an encrypted Front Door endpoint but allowing HTTP behind the scenes undermines end-to-end encryption requirements.

  • C. Incorrect.

    Option C is incorrect. Relying solely on the default Front Door domain limits branding and doesn't address the need for a custom domain. Self-signed certificates can create trust issues, and leaving all inbound protocols open on backends increases the attack surface.

  • D. Incorrect.

    Option D is incorrect. Using DNS A records pointed directly to the backends bypasses the benefits of traffic routing and SSL offload that Front Door provides. HTTP-only connections from Front Door to the origin defeats the purpose of end-to-end encryption.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam