← All SC-100 Flashcard Decks

Network Security Architecture Flashcards

7 cards from real SC-100 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Security Architecture flashcards as text
  1. An organization wants to implement micro-segmentation for its Azure workloads to limit lateral movement. Which Azure service best enables this at the workload level?

    Answer: Application Security Groups (ASGs)

    Application Security Groups allow you to group VMs logically and define NSG rules based on those groups, enabling micro-segmentation without managing IP addresses.

  2. Which Azure Private Link feature prevents data exfiltration by ensuring traffic to Azure PaaS services never traverses the public internet?

    Answer: Private Endpoints

    Private Endpoints assign a private IP from your VNet to an Azure PaaS service, keeping all traffic on the Microsoft backbone and preventing data exfiltration via the public internet.

  3. A security architect must ensure that all outbound internet traffic from Azure VMs is inspected and filtered. What is the recommended approach?

    Answer: Deploy Azure Firewall and use User Defined Routes to force-tunnel traffic

    Deploying Azure Firewall with UDRs (0.0.0.0/0 pointing to the firewall) forces all outbound internet traffic through centralized inspection and filtering.

  4. In a Zero Trust network model on Azure, which principle applies when a user accesses an internal application from a compliant corporate device?

    Answer: Verify explicitly using identity, device health, and context before granting access

    Zero Trust requires explicitly verifying identity, device compliance, and contextual signals every time—even from corporate devices—before granting access.

  5. Which Azure networking feature allows you to inspect and filter traffic between spokes in a hub-and-spoke topology without hairpinning through on-premises?

    Answer: Azure Firewall deployed in the hub VNet

    Azure Firewall in the hub VNet, combined with UDRs on spoke subnets, routes inter-spoke traffic through the firewall for inspection without requiring on-premises traversal.

  6. A cybersecurity architect is designing network controls to protect sensitive data in transit between Azure services. What should be enforced?

    Answer: Enforce TLS 1.2 or higher for all data in transit and disable older protocols

    Enforcing TLS 1.2+ ensures data in transit is encrypted with modern ciphers, protecting against interception even if network controls are bypassed.

  7. When using Azure Firewall Premium, which feature provides IDPS (Intrusion Detection and Prevention) capabilities?

    Answer: Signature-based IDPS engine with alert and deny modes

    Azure Firewall Premium includes a signature-based IDPS engine that can detect and optionally block known threats based on threat intelligence signatures.