AZ-500 Secure compute, storage, and databases Practice Question
A company deploys a public-facing web application behind Azure Application Gateway. They want to enable the Web Application Firewall (WAF) to protect against SQL injection and cross-site scripting attacks. During the initial testing phase, they want to identify malicious requests without blocking them, to tune the WAF rules before enabling full protection. Which WAF mode should they configure?
⚠ Common exam trap
Test-takers frequently confuse Detection mode with a hypothetical 'Logging mode' or assume Prevention mode is needed for any protection, overlooking the explicit requirement to identify without blocking during tuning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection mode
Detection mode logs WAF alerts and records the full request details without blocking any traffic. This allows the security team to analyze malicious requests, tune rule exclusions, and validate that legitimate traffic is not falsely flagged before switching to Prevention mode. It is the correct choice for the initial testing phase described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prevention mode
Why it's wrong here
Prevention mode is the enforcement state of an Azure WAF policy: requests matching managed rules are logged and actively blocked with a 403 before reaching the backend. Running a public-facing application in this mode during discovery/assessment would allow WAF false positives to disrupt legitimate traffic, which violates the requirement to first identify attacks without impacting users. The correct phase for observation is Detection mode, which never changes the request outcome.
- ✓
Detection mode
Why this is correct
Detection mode configures the WAF policy to pass every request through to the backend while evaluating it against the enabled rule sets, and any matches are recorded in the WAF log for later analysis. Because no request is denied, legitimate traffic cannot be interrupted, making it the appropriate setting for identifying attacks and tuning rules before enabling enforcement. This is the exact behavior needed by the team during the validation phase.
- ✗
Logging mode
Why it's wrong here
There is no such thing as a 'Logging mode' in Azure WAF; diagnostics logging is controlled separately through Azure Monitor diagnostic settings and will produce WAF logs whether the policy is in Detection or Prevention mode. Selecting a so-called logging mode would not alter the policy's blocking behavior, so it fails to provide a meaningful WAF configuration choice. The operational decision that matters is whether the policy operates in Detection or Prevention.
- ✗
Off
Why it's wrong here
Turning the WAF off removes all rule evaluation and, as a result, no WAF-specific log entries are generated for attempted attacks against the application. This leaves the public-facing endpoint without any web application firewall visibility, contradicting the requirement to identify malicious requests. The only way to satisfy the assessment goal is to keep the WAF enabled, preferably in Detection mode.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.