โ† All AZ-700 Flashcard Decks

Network Security and Compliance Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security and Compliance flashcards as text
  1. You are configuring Azure Application Gateway WAF in Prevention mode. A legitimate request is being blocked. What is the quickest way to allow it without disabling WAF?

    Answer: Add a WAF exclusion rule for the specific request attribute

    WAF exclusion rules allow you to exclude specific request attributes (headers, cookies, query strings) from WAF evaluation without disabling protection.

  2. Which DDoS Protection tier provides adaptive tuning, attack telemetry, and rapid response support for Azure resources?

    Answer: DDoS Network Protection

    DDoS Network Protection provides adaptive tuning per-virtual network, detailed attack telemetry, and access to the DDoS Rapid Response team.

  3. You need to ensure that a virtual network only communicates with a specific Azure Storage account using a private IP. What should you deploy?

    Answer: Private Endpoint

    A Private Endpoint assigns a private IP from your VNet to the Azure Storage account, allowing private-only access without traversing the public internet.

  4. An organization must ensure all inter-VNet traffic is inspected by Azure Firewall. What hub-and-spoke component achieves this?

    Answer: User-Defined Routes forcing traffic to the Firewall as next hop

    User-Defined Routes (UDRs) with the Azure Firewall private IP as the next hop force spoke VNet traffic through the firewall for inspection.

  5. Which Azure Policy built-in initiative helps enforce network security compliance for PCI DSS workloads?

    Answer: PCI DSS built-in initiative

    Azure Policy includes a built-in PCI DSS initiative that maps controls to Azure configurations, helping enforce network and security compliance for cardholder data environments.

  6. You need to block SSH and RDP access to Azure VMs from the internet while still allowing access for administrators. What is the recommended solution?

    Answer: Use Just-in-Time VM access with Defender for Cloud

    Just-in-Time VM access in Microsoft Defender for Cloud temporarily opens SSH/RDP ports only on request, reducing the attack surface.

  7. In Azure Firewall Manager, what is a Secured Virtual Hub?

    Answer: An Azure Virtual WAN Hub with Azure Firewall integrated

    A Secured Virtual Hub is an Azure Virtual WAN hub that has Azure Firewall integrated, managed centrally through Azure Firewall Manager.