AZ-700 exam dumps

AZ-700 practice question 290 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 290

Single answer

You have deployed Azure Firewall in a hub virtual network. Your environment includes a web server in a spoke virtual network with a private IP address of 10.0.0.5. You want to allow inbound HTTPS traffic from the public internet to this web server on port 443, while blocking all other inbound traffic. Additionally, you must restrict outbound traffic from the spoke virtual network to only specific domain names used by the application. Which Azure Firewall configuration should you implement to meet these requirements?

  1. A

    A NAT rule collection mapping inbound traffic on port 443 to the web server� private IP, and an application rule collection to restrict outbound traffic by domain

  2. B

    A network rule collection allowing inbound traffic on port 443, plus a network rule collection blocking traffic to disallowed domains

  3. C

    An application rule collection for inbound traffic from the public internet on port 443, plus a network rule collection for outbound domain restrictions

  4. D

    Forced tunneling configured at the route table level to send outbound traffic through your on-premises firewall while opening port 443 via a network security group (NSG)

Show answer and explanation

Correct answer: A

Explanation

Azure Firewall processes inbound connections via NAT rules, which translate external traffic to the private IP of backend resources. To filter outbound connections by domain name, you must use application rule collections. For more details, see the official Microsoft documentation on Azure Firewall rule processing order and FQDN filtering: https://learn.microsoft.com/azure/firewall/rule-processing

  • A. Correct.

    Correct: For inbound access on port 443, you need a NAT rule to forward traffic from Azure Firewall� public IP to the web server� private IP. For restricting outbound traffic by domain name, an application rule collection is required, as it allows domain (FQDN) filtering.

  • B. Incorrect.

    Incorrect: Network rule collections filter traffic by source/destination IP and port, not by FQDN. This would not allow you to restrict outbound traffic based on specific domain names. While you can allow inbound HTTPS with a network rule, you need NAT rules for inbound public-to-private mapping.

  • C. Incorrect.

    Incorrect: Application rule collections are not used to handle inbound public IP traffic. They are for outbound or east-west traffic needing FQDN-based filtering. Inbound connections from the public internet require NAT rules to translate external traffic to the internal private IP.

  • D. Incorrect.

    Incorrect: Forced tunneling would route outbound traffic through on-premises, not Azure Firewall alone, and NSGs cannot replace the need for NAT or application rules. NSGs handle IP-based filtering, not domain-based restrictions, and do not manage the public-to-private mapping required for inbound HTTPS.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam