AZ-700 exam dumps

AZ-700 practice question 303 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 303

Single answer

You have configured a WAF policy for Azure Front Door using the default OWASP managed rule set to block malicious traffic. However, you need to permit requests from a trusted partner� IP range�even if they match any of the default rule signatures. Which approach should you use to ensure requests from the trusted IP range are allowed while still blocking other malicious traffic?

  1. A

    Create a custom rule with Action set to Allow and assign it a lower numeric priority than the default rule set to override any blocking signatures for that IP range.

  2. B

    Modify the default rule set to remove the partner� IP range from all signatures in the OWASP managed rules.

  3. C

    Create a custom rule with Action set to Redirect, ensuring that any traffic from the IP range bypasses the OWASP rules.

  4. D

    Disable the OWASP managed rule set entirely and rely solely on custom rules to control access.

Show answer and explanation

Correct answer: A

Explanation

To allow trusted traffic while still blocking malicious activity, you use a custom rule set with a higher precedence (lower numeric priority) than the default managed rule set. This approach allows traffic matching specific conditions (e.g., the partner� IP range) to bypass the default blocking rules. For more information, refer to Microsoft� Azure Front Door WAF documentation on custom rule configuration and priority handling.

  • A. Correct.

    Correct. In Azure Front Door WAF, a custom rule with a lower numeric priority (which is treated as higher precedence) than the default rule set will allow matching traffic to pass before the default rules are evaluated. This ensures that traffic from the specified IP range is allowed.

  • B. Incorrect.

    Incorrect. You cannot modify the in-built OWASP managed rule sets directly. While you can enable, disable, or configure exclusions for certain request attributes, you can't remove an IP range from all signatures globally. It's more practical and recommended to create a custom rule with appropriate priority.

  • C. Incorrect.

    Incorrect. Setting the Action to Redirect will send the requests to a different location but does not provide a direct Allow override. Additionally, malicious requests from that IP range might still be processed incorrectly, depending on the rule logic. Allow is more appropriate here.

  • D. Incorrect.

    Incorrect. Disabling the OWASP rule set removes a critical layer of protection. The recommended approach is to keep the validated and tested managed rule sets for well-known vulnerabilities while customizing only the exceptions as needed.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam