An organization wants to enforce a mandatory set of corporate security rules on all Azure Firewalls while allowing individual application teams to add their own specific rules. The corporate rules must always be processed before the application-specific rules. Which Azure Firewall Policy configuration should be used?
-
A
Create a single, global Firewall Policy and grant all teams contributor access.
-
B
Create a parent Firewall Policy for corporate rules and child policies for each application team that inherit from the parent.
-
C
Use classic firewall rules on each firewall and use Azure Policy to audit for compliance.
-
D
Create separate, independent Firewall Policies for corporate rules and for each application team.