Network Security and Compliance Flashcards
7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security and Compliance flashcards as text
You need to restrict outbound internet traffic from Azure VMs to only approved FQDNs. Which Azure Firewall feature should you use?
Answer: Application rules with FQDN tags
Azure Firewall application rules use FQDN-based filtering to control outbound HTTP/HTTPS traffic to specific domain names.
An NSG is applied to both a subnet and a NIC. Traffic arrives at the subnet. In what order are the NSG rules evaluated for inbound traffic?
Answer: Subnet NSG first, then NIC NSG
For inbound traffic, the subnet NSG is evaluated first, and if traffic passes, the NIC NSG is evaluated second.
Which Azure service provides a managed WAF that protects web applications from OWASP Top 10 vulnerabilities at the edge?
Answer: Azure Front Door with WAF policy
Azure Front Door integrates WAF policies that include OWASP Core Rule Sets for protection against common web exploits at the edge.
You want to enable threat intelligence-based filtering in Azure Firewall to block known malicious IPs. What must you configure?
Answer: Set Threat Intel mode to Alert and Deny in Firewall Policy
Azure Firewall Threat Intelligence mode must be set to 'Alert and Deny' in the Firewall Policy to block traffic from/to known malicious IPs.
A company needs to prevent data exfiltration from Azure PaaS services by ensuring traffic stays on the Microsoft backbone. Which feature should be implemented?
Answer: Service Endpoints with Service Endpoint Policies
Service Endpoint Policies allow you to filter traffic to specific Azure resources, preventing data exfiltration to unauthorized storage accounts or services.
Which Azure Firewall SKU supports IDPS (Intrusion Detection and Prevention System) and TLS inspection?
Answer: Azure Firewall Premium
Azure Firewall Premium includes IDPS and TLS inspection features not available in the Standard or Basic tiers.
You need to audit all NSG flow logs for compliance. Which service stores NSG flow logs and enables traffic analytics?
Answer: Azure Network Watcher with storage account
NSG flow logs are stored in an Azure Storage account via Network Watcher, and Traffic Analytics can process these logs for visualization and insights.