AZ-800 AZ-800 - Microsoft Azure Networking Solutions Azure Bastion and DDoS Protection Questions and Answers 2 — Questions and Answers
Question 1: What are the two tiers of Azure DDoS Protection?
- DDoS Network Protection and DDoS IP Protection (Correct answer)
- DDoS Basic and DDoS Advanced
- DDoS Standard and DDoS Premium
- DDoS Free and DDoS Enterprise
Correct answer: DDoS Network Protection and DDoS IP Protection
Azure DDoS Protection is offered as DDoS Network Protection (per VNet plan) and DDoS IP Protection (per public IP), replacing the older Basic/Standard naming.
Question 2: Which DDoS Protection tier is automatically applied to all Azure public IP addresses at no extra cost?
- Default (infrastructure-level) DDoS protection (Correct answer)
- DDoS IP Protection
- DDoS Network Protection
- DDoS Basic (legacy)
Correct answer: Default (infrastructure-level) DDoS protection
Azure provides default (always-on) infrastructure-level DDoS mitigation for all public IPs at no cost, protecting against common network-layer attacks.
Question 3: Azure DDoS Network Protection uses adaptive tuning. What does this mean?
- It learns the normal traffic baseline for each protected IP and adjusts mitigation thresholds accordingly (Correct answer)
- It applies the same fixed thresholds to all protected resources
- It requires manual threshold configuration per resource
- It only activates when traffic exceeds 1 Gbps
Correct answer: It learns the normal traffic baseline for each protected IP and adjusts mitigation thresholds accordingly
Adaptive tuning continuously analyzes traffic patterns unique to each resource and auto-calibrates detection thresholds to minimize false positives.
Question 4: Which Azure service can you combine with DDoS Network Protection to get application-layer (Layer 7) DDoS mitigation?
- Azure Application Gateway with WAF (Correct answer)
- Azure Load Balancer
- Azure VPN Gateway
- Azure Firewall Basic
Correct answer: Azure Application Gateway with WAF
DDoS Network Protection covers Layers 3–4; pairing it with Application Gateway WAF adds Layer 7 (HTTP/S) attack mitigation for a comprehensive defense.
Question 5: What telemetry does Azure DDoS Network Protection expose during an active attack?
- Real-time metrics in Azure Monitor including inbound packets dropped and attack vectors (Correct answer)
- Only email alerts after the attack is mitigated
- Logs stored only in the DDoS dashboard with no streaming
- Packet captures stored in Azure Blob Storage automatically
Correct answer: Real-time metrics in Azure Monitor including inbound packets dropped and attack vectors
During an attack, DDoS Protection surfaces real-time metrics via Azure Monitor such as inbound bytes/packets, dropped bytes, and active mitigation status.
Question 6: A company wants to be reimbursed for Azure compute and bandwidth costs incurred due to a DDoS attack. What must they have enabled?
- DDoS Network Protection plan on the affected VNet (Correct answer)
- DDoS IP Protection on each public IP
- Azure Defender for Network
- Azure Front Door with WAF
Correct answer: DDoS Network Protection plan on the affected VNet
Azure's DDoS cost protection credit for scale-out costs during verified attacks requires DDoS Network Protection (the VNet-level plan) to be active.
What are the two tiers of Azure DDoS Protection?