AZ-700 exam dumps

AZ-700 practice question 281 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 281

Select 3

You are designing a security solution for a corporate environment that hosts workloads in Azure. The organization must restrict outbound traffic to specific FQDNs (fully qualified domain names) and thoroughly inspect all outbound HTTPS traffic for malicious content. Additionally, the solution must automatically block known malicious IP addresses or domains based on real-time threat intelligence. Which three Azure Firewall capabilities should you implement to fulfill these requirements?

  1. A

    FQDN-based application rules

  2. B

    TLS inspection

  3. C

    Threat intelligence-based filtering

  4. D

    DNAT rules with multiple public IP addresses

  5. E

    Forced tunneling to an on-premises proxy

  6. F

    Automatic DDoS protection

Show answer and explanation

Correct answers: A, B, C

Explanation

Azure Firewall� application rules with FQDN filtering, TLS inspection (premium SKU), and threat intelligence-based filtering directly address the organization� needs to restrict outbound traffic to specific domains, inspect HTTPS connections for malicious content, and leverage real-time threat intelligence. Refer to Microsoft� Azure Firewall documentation for detailed guidance on creating application rules, enabling TLS inspection, and configuring threat intelligence (https://learn.microsoft.com/azure/firewall).

  • A. Correct.

    FQDN-based application rules: Correct. Azure Firewall� application rules allow you to define outbound traffic restrictions based on specific FQDNs, meeting the requirement to only allow access to certain domain names.

  • B. Correct.

    TLS inspection: Correct. Azure Firewall Premium supports TLS inspection, enabling deeper inspection of outbound HTTPS traffic to detect and block malicious content or suspicious payloads.

  • C. Correct.

    Threat intelligence-based filtering: Correct. Threat intelligence in Azure Firewall helps automatically block or alert on traffic from known malicious IP addresses and domains, fulfilling the real-time blocking requirement.

  • D. Incorrect.

    DNAT rules with multiple public IP addresses: Incorrect. DNAT (Destination NAT) rules are typically used to forward inbound traffic from public IPs to internal resources, not to restrict outbound traffic to specific FQDNs or inspect HTTPS.

  • E. Incorrect.

    Forced tunneling to an on-premises proxy: Incorrect. While forced tunneling routes internet-bound traffic back on-premises, it does not inherently provide FQDN filtering or TLS inspection by Azure Firewall. Additional on-premises systems would be needed to meet those requirements.

  • F. Incorrect.

    Automatic DDoS protection: Incorrect. Azure Firewall does not automatically include DDoS protection. DDoS Protection is a separate Azure service that can be enabled at the virtual network level but does not by itself restrict outbound FQDNs or perform TLS inspection.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam