← All AZ-700 Flashcard Decks

Azure Application Gateway and WAF Flashcards

7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Azure Application Gateway and WAF flashcards as text
  1. What are the two operating modes available for Azure WAF on Application Gateway?

    Answer: Detection mode and Prevention mode

    WAF operates in Detection mode (logs threats without blocking) or Prevention mode (logs and actively blocks malicious requests).

  2. Which category of attacks does Azure WAF on Application Gateway primarily protect against?

    Answer: SQL injection, cross-site scripting, and OWASP Top 10 vulnerabilities

    Azure WAF protects against common web application attacks including SQL injection, XSS, and other OWASP Top 10 threats using managed rule sets.

  3. What is the purpose of WAF exclusion lists in Azure Application Gateway?

    Answer: Excluding specific request attributes from WAF rule evaluation to prevent false positives

    WAF exclusion lists allow you to omit specific request attributes such as headers, cookies, or query strings from WAF rule evaluation to eliminate false positive blocks.

  4. How are WAF custom rules evaluated relative to managed ruleset rules in Azure Application Gateway?

    Answer: Custom rules are evaluated before managed ruleset rules and take priority

    WAF custom rules are evaluated before managed ruleset rules, allowing you to define precise allow or deny logic that takes priority over the default ruleset.

  5. Which HTTP response code does Azure WAF return to clients when it blocks a request in Prevention mode?

    Answer: 403 Forbidden

    When WAF blocks a request in Prevention mode, it returns HTTP 403 Forbidden to the client, indicating the request was understood but refused.

  6. What is a managed ruleset in Azure WAF?

    Answer: A pre-configured set of rules maintained by Microsoft protecting against known web vulnerabilities

    Managed rulesets are pre-configured security rules maintained and updated by Microsoft to protect against common web vulnerabilities without requiring manual rule authoring.

  7. Which WAF policy association scope allows different WAF configurations to be applied to individual listeners on the same Application Gateway?

    Answer: Per-site (per-listener) WAF policy

    Per-site WAF policies allow different WAF configurations, including custom rules and exclusions, to be applied to individual listeners on the same Application Gateway instance.