AZ-700 exam dumps

AZ-700 practice question 304 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 304

Select 2

Your organization has an Azure Front Door instance protecting a public website with an active Web Application Firewall (WAF) policy. You currently use the latest managed rule set to guard against common exploits. After detecting suspicious activity from specific IP addresses, you decide to block them individually. Additionally, you must ensure that certain trusted partner IP addresses are never blocked by this new rule. Which two configurations should you implement in your WAF policy to meet these requirements?

  1. A

    Enable the Microsoft_DefaultRuleSet 1.1 managed rule set and add malicious IP addresses as exclusions in the same rule set.

  2. B

    Create a custom rule with a condition that matches the malicious IP addresses and set the action to Block.

  3. C

    Edit the existing managed rule set to insert a new rule at the top that specifically allows traffic from all IP addresses before evaluating the rest of the rules.

  4. D

    Create a custom rule that matches the trusted partner IP addresses and set the action to Allow with a higher priority (lower numerical value) than the block rule.

Show answer and explanation

Correct answers: B, D

Explanation

To meet real-world requirements for blocking malicious IP addresses while exempting trusted IPs, you should configure custom rules in your Azure Front Door WAF policy. By creating two separate custom rules�one to block malicious traffic and another to allow trusted IP addresses�you ensure precise control over who is allowed or denied. Priority-based rule evaluation in Azure Front Door WAF processes your 'allow' rules first (lower number = higher priority) to prevent unintended blocking. For more details, refer to the official Azure Front Door WAF documentation: https://learn.microsoft.com/azure/web-application-firewall/afds/afds-overview.

  • A. Incorrect.

    Option 1: Incorrect. Enabling the older Microsoft_DefaultRuleSet 1.1 without creating a separate custom rule for malicious IP addresses does not adequately address the specific block requirement. Exclusions in managed rule sets are typically meant for excluding parameters or requests from detection checks, not for explicitly blocking IPs.

  • B. Correct.

    Option 2: Correct. Custom rules allow precise matching against IP addresses. Creating a rule that targets the malicious IP addresses and setting the action to Block ensures those addresses are denied access. This is the recommended approach for explicit blocking scenarios.

  • C. Incorrect.

    Option 3: Incorrect. Editing the existing managed rule set to allow all traffic before evaluating other rules would effectively negate the WAF's protection. You typically do not add a global 'Allow all' rule to the managed set; instead, you must create a custom rule for the new requirement and use rule priorities properly.

  • D. Correct.

    Option 4: Correct. By creating a custom rule that explicitly allows traffic from trusted partner IP addresses and assigning it a higher priority (in WAF terms, a lower numerical value), those requests are allowed before the malicious-block rule is evaluated.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam