AZ-500 exam dumps

AZ-500 practice question 111 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 111

Select 2

You manage an e-commerce application protected by an Azure Application Gateway configured with a Web Application Firewall (WAF). Your security team has observed repeated attempts that resemble injection attacks and they want these malicious requests to be blocked immediately. They also require detailed logging for further forensic analysis. Currently, the WAF is operating in Detection mode only. Which two actions should you take to meet these requirements?

  1. A

    Switch the WAF to Prevention mode at the WAF policy level.

  2. B

    Enable WAF diagnostic logging using Azure Monitor.

  3. C

    Add an exclusion rule to disable all built-in managed rulesets.

  4. D

    Reduce the idle timeout on the WAF to minimize the chance of injection attacks.

Show answer and explanation

Correct answers: A, B

Explanation

To effectively block malicious requests and collect comprehensive forensic data, you must move the Azure Application Gateway WAF from Detection (monitoring) mode to Prevention mode. This allows WAF to actively block attacks rather than simply log them. Additionally, enabling diagnostic logging ensures that detailed information about detected and blocked threats is captured. For more information, see the official Azure documentation on configuring WAF for Application Gateway (https://docs.microsoft.com/azure/web-application-firewall/ag/configure-web-application-firewall-ag).

  • A. Correct.

    Correct. Switching the WAF to Prevention mode ensures that malicious traffic is actively blocked rather than merely detected. This is done by updating the WAF policy associated with the Application Gateway.

  • B. Correct.

    Correct. Enabling WAF diagnostic logging in Azure Monitor (or sending logs to Log Analytics or a Storage Account) allows you to capture detailed information about request patterns, blocked traffic, and potential threats for future analysis.

  • C. Incorrect.

    Incorrect. Disabling all built-in managed rules is generally not advisable because those rules provide critical, preconfigured protections (for instance, against SQL injection, cross-site scripting, etc.). Removing them would expose the application to common attack vectors.

  • D. Incorrect.

    Incorrect. Reducing the idle timeout might mitigate some session-related issues, but it does not specifically address injection attacks or provide detailed logging. It is not the correct action to satisfy the requirement of blocking malicious requests and gathering detailed logs.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam