AZ-700 exam dumps

AZ-700 practice question 299 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 299

Select 2

A global e-commerce platform wants to serve customers from multiple regions with low latency and high availability. They also need to protect their application against malicious threats such as SQL injection and cross-site scripting. You recommend using Azure Web Application Firewall (WAF) for enhanced security. Which two design approaches should you implement to meet these requirements?

  1. A

    Use Azure Front Door Premium with a WAF policy in prevention mode to inspect and block malicious requests at the edge.

  2. B

    Configure the WAF to run in detection mode only across all environments to avoid blocking any requests in production.

  3. C

    Deploy a single Azure Application Gateway with WAF in one region and route all global traffic to that single gateway.

  4. D

    Replace the default OWASP Core Rule Set with a custom rule set that only targets SQL injection attempts.

  5. E

    Create custom WAF policies for geofencing, rate limiting, or advanced threats and attach them to Front Door or Application Gateway endpoints as needed.

Show answer and explanation

Correct answers: A, E

Explanation

Using Azure WAF in prevention mode helps block malicious traffic in real time. Azure Front Door Premium provides a global presence for low latency and high availability. Supplementing the default OWASP Core Rule Set with custom WAF policies (e.g., for geofencing and rate limiting) tailors security to specific needs. Refer to Azure documentation on 'Web Application Firewall in Azure Front Door' and 'Web Application Firewall on Azure Application Gateway' for best practices in designing scalable, secure WAF deployments.

  • A. Correct.

    Correct. Azure Front Door Premium with a WAF policy in prevention mode offers global routing, edge security, and immediate blocking of malicious requests. This design reduces latency for users by serving them from the nearest edge point while applying protection at the perimeter.

  • B. Incorrect.

    Incorrect. Running only in detection mode will not block malicious traffic. Detection mode can be used for initial testing or tuning, but production environments typically need prevention mode to actively block threats.

  • C. Incorrect.

    Incorrect. A single regional deployment can become a performance bottleneck for remote customers and may introduce higher latency. It also creates a single point of failure if anything happens to that gateway.

  • D. Incorrect.

    Incorrect. Restricting the WAF to blocking only SQL injection attempts overlooks other threats (e.g., cross-site scripting or remote code execution). The recommended approach is to use at least the default OWASP Core Rule Set to cover a broad range of common vulnerabilities and exposures.

  • E. Correct.

    Correct. In addition to the default OWASP Core Rule Set, creating and attaching custom WAF policies (like geofencing or rate limiting) can help address specific threats or business requirements, enhancing overall protection.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam