AZ-700 exam dumps

AZ-700 practice question 310 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 310

Single answer

You manage an e-commerce website that uses Azure Application Gateway deployed in WAF v2 SKU. You need to apply a customized WAF policy to protect the payment page served by a specific multi-site listener without affecting other traffic. How should you associate the WAF policy to achieve this goal?

  1. A

    Assign the WAF policy at the global Application Gateway level so it covers all listeners

  2. B

    Associate the WAF policy with the specific multi-site listener that serves the payment domain

  3. C

    Enable an Azure Firewall rule to override the default WAF rules only for payment traffic

  4. D

    Attach the WAF policy to all backend VMs hosting the payment application

Show answer and explanation

Correct answer: B

Explanation

In Azure Application Gateway WAF v2, you can associate a custom WAF policy at different scopes: global, listener, or path-based rule. To isolate the WAF protections to a single domain or listener, it is best practice to associate the policy at the listener level. This ensures that only the specific traffic flow to that listener�in this scenario, the payment page�is protected by the customized WAF rules without impacting other traffic. For more details, refer to Microsoft� documentation on associating WAF policies to Application Gateway listeners.

  • A. Incorrect.

    Option 1 is incorrect because applying the policy globally affects all listeners, not just the payment-specific listener, which could cause unnecessary or conflicting rule enforcement on unrelated traffic.

  • B. Correct.

    Option 2 is correct because associating the WAF policy with the specific multi-site listener ensures that only traffic for the designated domain (i.e., your payment site) is subject to those custom WAF rules. This approach localizes the policy� effect.

  • C. Incorrect.

    Option 3 is incorrect because Azure Firewall does not directly override or manage WAF policies associated with Application Gateway. Azure Firewall and Application Gateway WAF can be used together, but the question specifically requires fine-grained control via WAF policy association at the listener level.

  • D. Incorrect.

    Option 4 is incorrect because Application Gateway WAF policies are not attached to individual VMs or backend services. They are integrated at the gateway level or at specific listeners/path-based rules.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam