โ† All AZ-700 Flashcard Decks

Network Security and Compliance Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security and Compliance flashcards as text
  1. You need to restrict outbound internet traffic from Azure VMs to only approved FQDNs. Which Azure Firewall feature should you use?

    Answer: Application rules with FQDN tags

    Azure Firewall application rules use FQDN-based filtering to control outbound HTTP/HTTPS traffic to specific domain names.

  2. An NSG is applied to both a subnet and a NIC. Traffic arrives at the subnet. In what order are the NSG rules evaluated for inbound traffic?

    Answer: Subnet NSG first, then NIC NSG

    For inbound traffic, the subnet NSG is evaluated first, and if traffic passes, the NIC NSG is evaluated second.

  3. Which Azure service provides a managed WAF that protects web applications from OWASP Top 10 vulnerabilities at the edge?

    Answer: Azure Front Door with WAF policy

    Azure Front Door integrates WAF policies that include OWASP Core Rule Sets for protection against common web exploits at the edge.

  4. You want to enable threat intelligence-based filtering in Azure Firewall to block known malicious IPs. What must you configure?

    Answer: Set Threat Intel mode to Alert and Deny in Firewall Policy

    Azure Firewall Threat Intelligence mode must be set to 'Alert and Deny' in the Firewall Policy to block traffic from/to known malicious IPs.

  5. A company needs to prevent data exfiltration from Azure PaaS services by ensuring traffic stays on the Microsoft backbone. Which feature should be implemented?

    Answer: Service Endpoints with Service Endpoint Policies

    Service Endpoint Policies allow you to filter traffic to specific Azure resources, preventing data exfiltration to unauthorized storage accounts or services.

  6. Which Azure Firewall SKU supports IDPS (Intrusion Detection and Prevention System) and TLS inspection?

    Answer: Azure Firewall Premium

    Azure Firewall Premium includes IDPS and TLS inspection features not available in the Standard or Basic tiers.

  7. You need to audit all NSG flow logs for compliance. Which service stores NSG flow logs and enables traffic analytics?

    Answer: Azure Network Watcher with storage account

    NSG flow logs are stored in an Azure Storage account via Network Watcher, and Traffic Analytics can process these logs for visualization and insights.