Network Security Architecture Flashcards
7 cards from real SC-100 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security Architecture flashcards as text
A security architect is evaluating Azure Web Application Firewall (WAF) deployment options. For global HTTP/S applications requiring the lowest latency WAF inspection, which service should host the WAF?
Answer: Azure Front Door with WAF policy
Azure Front Door delivers WAF inspection at Microsoft's global edge PoPs, minimizing latency by inspecting traffic close to the user before forwarding to origin.
Which Azure Firewall feature helps reduce the administrative overhead of maintaining IP address-based rules for frequently changing service IPs?
Answer: Service tags representing Azure service IP ranges
Service tags abstract Azure service IP ranges that Microsoft manages, so rules referencing service tags automatically stay current without manual IP list maintenance.
An organization must ensure that all administrative access to Azure VMs uses encrypted, audited sessions without exposing RDP/SSH ports to the internet. Which service satisfies this requirement?
Answer: Azure Bastion with audit logs sent to Log Analytics
Azure Bastion provides browser-based RDP/SSH over TLS without exposing VM ports publicly, and its session activity can be logged to Azure Monitor for audit purposes.
When designing a secure network architecture for Azure SQL Database, which combination provides the strongest data-plane isolation?
Answer: Private endpoint with public network access disabled and Azure AD authentication enforced
Combining a private endpoint with public network access disabled ensures all database traffic stays on private networks, and AAD authentication eliminates password-based credential risks.
In a hybrid network design, what is the security advantage of using ExpressRoute over a site-to-site VPN for connecting on-premises to Azure?
Answer: ExpressRoute traffic does not traverse the public internet, reducing exposure to internet-based threats
ExpressRoute routes traffic through a private, dedicated circuit via a connectivity provider, meaning it never traverses the public internet and avoids internet-based interception risks.
A cybersecurity architect is designing controls to detect and respond to network-based threats across Azure subscriptions. Which Microsoft service provides unified network threat detection using ML-based analytics?
Answer: Microsoft Sentinel with Azure network data connectors and analytics rules
Microsoft Sentinel ingests network telemetry across subscriptions and applies ML-based analytics rules to detect sophisticated threats and enable automated response.
When implementing network security for an Azure landing zone, what does the 'policy-driven guardrails' approach mean for network configuration?
Answer: Using Azure Policy to automatically enforce and audit network security configurations across all subscriptions
Azure Policy guardrails automatically enforce compliant network configurations (e.g., requiring NSGs, denying public IPs) and audit drift across the entire landing zone estate.