AZ-700 exam dumps

AZ-700 practice question 296 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 296

Select 2

You maintain a globally distributed e-commerce application deployed in multiple Azure regions, with Azure Front Door providing global load balancing and routing. To safeguard this application, you want to use Azure Web Application Firewall (WAF) to block common web exploits (e.g., SQL injection, cross-site scripting) and additionally deny all requests from an identified malicious IP address range. Which two steps must you take to achieve these security requirements using Azure Front Door WAF? (Choose two.)

  1. A

    Create an Azure Firewall policy that includes a custom rule to block requests from the malicious IP range and associate it with Front Door

  2. B

    Enable the managed rule sets in an Azure Front Door WAF policy to protect against common vulnerabilities

  3. C

    Deploy an Azure Application Gateway WAF for each region and configure it with managed rule sets

  4. D

    Configure a custom rule in the Azure Front Door WAF policy to block requests originating from the malicious IP range

Show answer and explanation

Correct answers: B, D

Explanation

To properly protect a global application with Azure Front Door, you should associate a WAF policy with Front Door, enabling the OWASP-managed rule sets for common exploit protection and creating any necessary custom rules (such as blocking specific IP ranges). Azure Firewall and Application Gateway WAF operate at different layers or shapes of the network stack and are not directly required in this scenario. For more details on configuring Azure WAF policies with Front Door, see the official Azure documentation: https://learn.microsoft.com/azure/web-application-firewall/afds/afds-overview.

  • A. Incorrect.

    Incorrect: Azure Firewall is generally used to control inbound and outbound traffic at the network level, and you cannot directly associate an Azure Firewall policy with Azure Front Door. Blocking malicious IPs at the application layer requires a WAF policy specifically attached to Front Door.

  • B. Correct.

    Correct: Managed rule sets for Azure Front Door WAF provide protection against common vulnerabilities like SQL injection and cross-site scripting. Enabling these rules is essential for comprehensive application-layer security.

  • C. Incorrect.

    Incorrect: Deploying Azure Application Gateway WAF in each region is not necessary if your application is fronted by Azure Front Door. Front Door WAF policies can provide centralized security for your global application, making separate per-region WAF deployments redundant in this scenario.

  • D. Correct.

    Correct: In addition to the managed rule sets, you need a custom rule in the Azure Front Door WAF policy to specifically block traffic from the known malicious IP address range. This ensures that any requests originating from those IP addresses are denied.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam