AZ-700 exam dumps

AZ-700 practice question 301 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 301

Single answer

Your organization has deployed a new web application behind an Azure Application Gateway with Web Application Firewall (WAF). The security team wants to verify how WAF rules detect potential threats without blocking them. Later, they plan to switch to blocking malicious traffic if the logs show significant suspicious activity. What is the best approach to achieve this goal with minimal downtime and configuration changes?

  1. A

    A) Enable Detection mode for only the default rule set and keep Prevention mode for any custom rules

  2. B

    B) Configure the WAF policy to run in Detection mode for all rules, then toggle the WAF policy to Prevention mode when needed

  3. C

    C) Immediately deploy the WAF in Prevention mode and remove all default rules to avoid accidental blocking

  4. D

    D) Create separate WAF policies for each rule set and repeatedly switch the assigned policy on the application gateway

Show answer and explanation

Correct answer: B

Explanation

Azure WAF policies can be configured in either Detection or Prevention mode for the entire policy. Detection mode logs potentially malicious requests without blocking them, allowing security teams to evaluate the alert data before deciding to enforce blocking. Switching to Prevention mode is as simple as updating the WAF policy� configuration, which avoids recreating rules or causing unnecessary downtime. For additional details, refer to the Microsoft documentation on Azure WAF (https://learn.microsoft.com/azure/web-application-firewall/).

  • A. Incorrect.

    Option A is incorrect because Azure WAF does not allow you to partially apply Detection mode to default rules and simultaneously apply Prevention mode to custom rules within the same policy. The mode (Detection or Prevention) applies to the entire policy, not individual rule sets.

  • B. Correct.

    Option B is correct. In real-world scenarios, you can set the WAF policy to Detection mode to log potential threats without blocking. Then, if the logs confirm malicious behavior, you can switch the policy to Prevention mode, blocking unwanted traffic without requiring a full redeployment or complicated changes.

  • C. Incorrect.

    Option C is incorrect because deploying the WAF in Prevention mode from the start may block legitimate requests if the default rules flag benign traffic. Also, removing all default rules undermines a key security layer. This approach does not align with a phased and controlled rollout.

  • D. Incorrect.

    Option D is incorrect because maintaining multiple WAF policies and swapping them frequently is more complex, requiring potential downtime or reconfiguration each time. It's less efficient than adjusting the mode within a single WAF policy.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam