Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A cloud administrator manages a Microsoft Azure subscription. The security team requires that all virtual machines in a resource group be protected by a host-based firewall that filters traffic by port and protocol, independent of any network security group rules. The administrator needs a solution that can be applied directly to the operating system of each VM. Which solution should the administrator implement?

⚠ Common exam trap

The trap here is assuming that Azure network security controls such as NSGs or Azure Firewall provide host-based protection, when they actually operate at the network layer and cannot filter traffic inside the VM operating system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install and configure a host-based firewall such as Windows Defender Firewall or iptables on each VM.

The requirement is for a host-based firewall that filters traffic by port and protocol directly on each VM's operating system. Only a firewall installed inside the guest OS, such as Windows Defender Firewall or iptables, meets this need. Azure-native services like Firewall, NSGs, and DDoS Protection operate at the network layer and cannot enforce OS-level filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Azure DDoS Protection Standard on the virtual network.

    Why it's wrong here

    Azure DDoS Protection Standard mitigates volumetric and protocol-layer attacks against public IP addresses in a virtual network. It does not provide host-based port and protocol filtering on individual VMs and operates at the network perimeter, not the operating system. It cannot replace a host-based firewall for the described requirement.

  • ✗

    Configure Azure Firewall in the virtual network.

    Why it's wrong here

    Azure Firewall is a managed, cloud-native network security service that inspects traffic at the virtual network level, not on the VM operating system. It cannot act as a host-based firewall because it does not run inside the guest OS and does not filter traffic by process or local port on the machine itself. The requirement specifies protection applied directly to each VM's operating system.

  • ✗

    Apply a network security group (NSG) to each VM's network interface.

    Why it's wrong here

    NSGs are stateful packet filters that operate at the Azure network layer, attached to subnets or NICs. They filter traffic before it reaches the VM's operating system, but they are not host-based firewalls and cannot enforce rules based on the OS-level processes or applications. The scenario explicitly requires a host-based firewall on the VM itself.

  • ✓

    Install and configure a host-based firewall such as Windows Defender Firewall or iptables on each VM.

    Why this is correct

    A host-based firewall runs inside the guest operating system and filters traffic by port, protocol, and application, independent of Azure network controls. Windows Defender Firewall and iptables are examples that satisfy the requirement to protect each VM directly at the OS level. This approach provides the granular, per-VM filtering the security team requested.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.