AZ-500 exam dumps

AZ-500 practice question 109 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 109

Select 2

You manage an e-commerce application hosted behind an Azure Application Gateway with Web Application Firewall (WAF) enabled. You have identified a list of malicious IP addresses that consistently attempt to access the application and need to block them. Additionally, you want to ensure that traffic from your internal employee network (identified by specific IP addresses) bypasses WAF inspection. Which two actions should you take in your WAF policy?

  1. A

    Create a custom WAF rule to block the listed malicious IP addresses.

  2. B

    Enable Detection mode on the WAF to observe traffic before adding any IP-based rules.

  3. C

    Configure an exclusion list for the internal IP addresses in the WAF policy.

  4. D

    Disable the OWASP core rule set (CRS) to ensure traffic from internal IP addresses is not blocked.

Show answer and explanation

Correct answers: A, C

Explanation

When planning and implementing a Web Application Firewall (WAF) on Azure Application Gateway, you can create custom rules in the WAF policy to block traffic from known malicious sources. Additionally, you can configure exclusions for trusted IP addresses to ensure internal traffic is not inadvertently blocked. Running the WAF in Prevention mode with custom rules (rather than relying solely on Detection mode or disabling the OWASP core rule set) is the best practice for balancing security and functionality. For more information, refer to Microsoft documentation on configuring custom WAF policies and rules in Azure Application Gateway (https://docs.microsoft.com/azure/web-application-firewall/ag/custom-waf-rules-overview).

  • A. Correct.

    Correct. Creating a custom WAF rule that blocks traffic from specific malicious IP addresses is the recommended approach to proactively prevent known harmful requests.

  • B. Incorrect.

    Incorrect. While Detection mode is useful for monitoring and reporting, it does not automatically block malicious IPs. You need Prevention mode (or custom rules in a WAF policy) to actively stop those requests.

  • C. Correct.

    Correct. Defining an exclusion for the internal IP range allows trusted traffic to bypass certain WAF checks, preventing false positives and disruptions for internal users.

  • D. Incorrect.

    Incorrect. Disabling the OWASP core rule set is not recommended because it removes valuable attack detection capabilities, leaving your application more vulnerable to common threats.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam