AZ-700 exam dumps

AZ-700 practice question 306 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 306

Single answer

You are the network engineer for a tech company that uses an Azure Application Gateway (WAF v2) to protect a mission-critical web application. A specific OWASP rule is frequently triggered and blocks legitimate requests, causing false positives. The rest of the rule set is working effectively. Which approach should you take to resolve these false positives while maintaining strong overall security?

  1. A

    Switch the WAF from 'Prevention' mode to 'Detection' mode for the entire application gateway.

  2. B

    Disable the entire OWASP rule set to avoid any further blocking.

  3. C

    Disable only the specific rule causing false positives within the WAF policy.

  4. D

    Create a custom rule that allows all traffic unconditionally to bypass the default rules.

Show answer and explanation

Correct answer: C

Explanation

When encountering false positives, the recommended approach is to disable or configure custom exclusions for the single rule causing issues, rather than reducing coverage broadly. Azure documentation on Web Application Firewall for Application Gateway (https://learn.microsoft.com/azure/web-application-firewall/ag/configure-waf-custom-rules) explains how to manage specific problematic rules while keeping the rest of the WAF protections in place.

  • A. Incorrect.

    Option 1 is incorrect. While switching to 'Detection' mode will prevent blocking, it also stops the WAF from actively mitigating real threats. This reduces the overall security level by only logging threats instead of blocking them.

  • B. Incorrect.

    Option 2 is incorrect. Disabling the entire OWASP rule set addresses the false positive but removes all other protection provided by the default rules, leaving the application exposed to many potential attacks.

  • C. Correct.

    Option 3 is correct. Disabling only the specific problematic rule within the WAF policy is a best practice. It minimizes false positives and maintains the rest of the OWASP protections. Azure Application Gateway supports disabling individual rules in the WAF policy without affecting the others.

  • D. Incorrect.

    Option 4 is incorrect. A custom rule that allows all traffic effectively bypasses the WAF's core functionality, which is a clear security risk.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam