Network Security Architecture Flashcards
7 cards from real SC-100 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security Architecture flashcards as text
An organization uses ExpressRoute for hybrid connectivity. To protect against route injection attacks from the on-premises network, what should a security architect implement?
Answer: BGP route filtering using route maps and prefix lists
BGP route filtering with prefix lists and route maps ensures only authorized prefixes are accepted from on-premises, preventing malicious route injection.
Which design pattern should a cybersecurity architect use to prevent a compromised workload in one Azure subscription from pivoting to resources in another subscription?
Answer: Use separate VNets per subscription with no peering and enforce Azure Firewall for any cross-subscription traffic
Isolating subscriptions with separate VNets and routing any required cross-subscription traffic through Azure Firewall limits blast radius if one subscription is compromised.
A company requires that its Azure Kubernetes Service (AKS) cluster nodes are not reachable from the public internet. Which configuration achieves this?
Answer: Deploy a private AKS cluster with a private endpoint for the API server
A private AKS cluster removes the public endpoint from the API server and uses a private endpoint, ensuring cluster management traffic stays within the private network.
In the SC-100 exam context, what is the primary purpose of Azure Network Watcher's Connection Monitor?
Answer: To continuously monitor network connectivity and latency between endpoints and alert on changes
Connection Monitor provides end-to-end connectivity monitoring, tracking reachability and round-trip time between sources and destinations, with alerting on degradation.
A security architect needs to restrict access to Azure Storage accounts so only traffic from specific VNets is allowed. Which feature should be used?
Answer: Azure Storage firewall with VNet service endpoints or private endpoints
Azure Storage firewall rules combined with VNet service endpoints or private endpoints restrict data-plane access to traffic originating from authorized VNets only.
Which approach best supports a 'never trust, always verify' model for server-to-server communication within an Azure VNet?
Answer: Implement mutual TLS (mTLS) with certificate-based authentication between services
Mutual TLS requires both client and server to authenticate with certificates, ensuring neither side implicitly trusts the other purely based on network location.
An architect wants to centralize DNS resolution for Azure private endpoints across multiple VNets in a hub-and-spoke topology. What is the recommended solution?
Answer: Deploy Azure Private DNS Resolver in the hub VNet with DNS forwarding rules
Azure Private DNS Resolver in the hub provides centralized conditional forwarding, allowing all spoke VNets to resolve private endpoint DNS names without per-spoke configuration.