AZ-700 exam dumps

AZ-700 practice question 307 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 307

Single answer

You have an Azure Application Gateway configured with a Web Application Firewall (WAF) in Prevention mode. Recently, certain legitimate user requests triggered a specific WAF managed rule and got blocked, causing customer complaints. You have verified that the rule is generating a false positive. What is the most appropriate way to resolve the issue while still protecting against other potential threats identified by the WAF?

  1. A

    Disable the entire managed rule set in the WAF policy to prevent any blocking.

  2. B

    Switch the WAF policy from Prevention mode to Detection mode so that requests are logged but not blocked.

  3. C

    Configure a custom WAF policy that disables all rules matching the broader rule group responsible for this false positive.

  4. D

    Create an exclusion or override for the specific false-positive rule to allow the traffic and continue enforcing other rules.

Show answer and explanation

Correct answer: D

Explanation

In Azure Application Gateway WAF, the best practice when facing a false positive is to configure an override or exclusion for the specific rule ID. This approach addresses the immediate issue without compromising the overall protection provided by the WAF. Refer to Microsoft's documentation on 'Customizing WAF rules and exclusions' (https://learn.microsoft.com/azure/web-application-firewall/ag/custom-waf-rules-overview) for guidance on safely excluding specific rules.

  • A. Incorrect.

    Option 1 is incorrect because disabling the entire managed rule set removes the protection offered by the WAF and leaves the application vulnerable to many other threats.

  • B. Incorrect.

    Option 2 is incorrect because switching to Detection mode means malicious traffic will no longer be blocked, just logged. This does not address the specific false-positive rule while keeping other malicious traffic blocked.

  • C. Incorrect.

    Option 3 is incorrect because disabling the entire rule group may affect more than just the single false-positive scenario, reducing security coverage more than necessary.

  • D. Correct.

    Option 4 is correct because creating an exclusion or override for the one problematic rule allows legitimate traffic that was falsely flagged while retaining protection from all other WAF rules.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam