What this objective tests
AZ-500 Secure networking — Key Topics
You must configure NSGs, Azure Firewall, private endpoints, VNet peering, DDoS Protection, and Bastion to secure traffic. Get rule evaluation order right: NSG priority, Azure Firewall DNAT/network/application rules, and effective routes.
- Configuring NSG security rules, priorities, and application security groups for subnet traffic
- Choosing Azure Firewall, NSG, or WAF for filtering and inspecting network flows
- Implementing Private Link and private endpoints versus service endpoints for PaaS access
- Securing remote administration with Azure Bastion, VPN Gateway, and Just-in-Time VM access