Network Security and Compliance Flashcards
7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security and Compliance flashcards as text
Which feature of Azure Firewall Premium allows inspection of encrypted HTTPS traffic for threats?
Answer: TLS Inspection with a CA certificate
TLS Inspection in Azure Firewall Premium decrypts outbound HTTPS traffic using an intermediate CA certificate to inspect content for threats.
You need to enforce that all new VNets in a subscription must have DDoS Network Protection enabled. Which Azure tool should you use?
Answer: Azure Policy with a Deny effect
An Azure Policy with Deny effect prevents creation of VNets that do not have DDoS Network Protection enabled.
A multi-tenant SaaS provider needs to offer customers private connectivity to their service without VNet peering. Which Azure feature enables this?
Answer: Azure Private Link Service
Azure Private Link Service lets providers expose their service behind a standard load balancer so customers can connect via Private Endpoints without VNet peering.
Which log type in Microsoft Sentinel helps detect lateral movement by analyzing network connection patterns between Azure resources?
Answer: NSG Flow Logs ingested via Traffic Analytics
NSG Flow Logs processed through Traffic Analytics reveal communication patterns between resources, helping detect lateral movement in Sentinel.
You need to control outbound internet traffic from an Azure Kubernetes Service (AKS) cluster using Azure Firewall. What must you configure in the AKS network settings?
Answer: Set outboundType to userDefinedRouting and add UDRs to the firewall
Setting outboundType to 'userDefinedRouting' in AKS tells the cluster to rely on UDRs for egress, allowing you to route traffic through Azure Firewall.
An NSG rule has priority 100 with Allow on port 443 and priority 200 with Deny on port 443 from the same source. What is the result?
Answer: Traffic is allowed because lower priority number wins
NSG rules are processed in priority order from lowest number to highest; priority 100 Allow is processed before priority 200 Deny, so traffic is allowed.
What is the purpose of the AzurePlatformDNS service tag in NSG rules?
Answer: Represents Azure's internal DNS infrastructure IP ranges for NSG rules
The AzurePlatformDNS service tag represents the IP address ranges used by Azure's DNS infrastructure, used in NSG rules to allow DNS resolution for platform services.