CV0-004 Security Practice Question
A cloud administrator manages a Microsoft Azure subscription. The security team requires that all virtual machines in a resource group be protected by a host-based firewall that filters traffic by port and protocol, independent of any network security group rules. The administrator needs a solution that can be applied directly to the operating system of each VM. Which solution should the administrator implement?
⚠ Common exam trap
The trap here is assuming that Azure network security controls such as NSGs or Azure Firewall provide host-based protection, when they actually operate at the network layer and cannot filter traffic inside the VM operating system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install and configure a host-based firewall such as Windows Defender Firewall or iptables on each VM.
The requirement is for a host-based firewall that filters traffic by port and protocol directly on each VM's operating system. Only a firewall installed inside the guest OS, such as Windows Defender Firewall or iptables, meets this need. Azure-native services like Firewall, NSGs, and DDoS Protection operate at the network layer and cannot enforce OS-level filtering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure DDoS Protection Standard on the virtual network.
Why it's wrong here
Azure DDoS Protection Standard mitigates volumetric and protocol-layer attacks against public IP addresses in a virtual network. It does not provide host-based port and protocol filtering on individual VMs and operates at the network perimeter, not the operating system. It cannot replace a host-based firewall for the described requirement.
- ✗
Configure Azure Firewall in the virtual network.
Why it's wrong here
Azure Firewall is a managed, cloud-native network security service that inspects traffic at the virtual network level, not on the VM operating system. It cannot act as a host-based firewall because it does not run inside the guest OS and does not filter traffic by process or local port on the machine itself. The requirement specifies protection applied directly to each VM's operating system.
- ✗
Apply a network security group (NSG) to each VM's network interface.
Why it's wrong here
NSGs are stateful packet filters that operate at the Azure network layer, attached to subnets or NICs. They filter traffic before it reaches the VM's operating system, but they are not host-based firewalls and cannot enforce rules based on the OS-level processes or applications. The scenario explicitly requires a host-based firewall on the VM itself.
- ✓
Install and configure a host-based firewall such as Windows Defender Firewall or iptables on each VM.
Why this is correct
A host-based firewall runs inside the guest operating system and filters traffic by port, protocol, and application, independent of Azure network controls. Windows Defender Firewall and iptables are examples that satisfy the requirement to protect each VM directly at the OS level. This approach provides the granular, per-VM filtering the security team requested.
Visual reference
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.