AZ-500 Secure networking Practice Question
A company deploys Azure Firewall to inspect and control outbound traffic from a virtual network. The security team wants to allow outbound HTTPS traffic only to specific FQDNs such as *.microsoft.com and *.windowsupdate.com, while blocking all other outbound internet access. Which type of rule should they configure in Azure Firewall to achieve this filtering?
⚠ Common exam trap
Many exam-takers confuse Network Rules with Application Rules, mistakenly thinking that port 443 and IP addresses can achieve FQDN-based filtering, but Network Rules lack the ability to inspect the application layer (FQDN) and can only filter by IP/port, which is insufficient for domain-specific allowlisting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application Rule
Azure Firewall uses Application Rules to filter outbound traffic based on fully qualified domain names (FQDNs) for HTTP/HTTPS protocols. Since the requirement is to allow HTTPS traffic to specific FQDNs like *.microsoft.com and *.windowsupdate.com, an Application Rule is the correct choice because it can inspect the TLS Server Name Indication (SNI) extension to match the target FQDN, enabling granular allow/deny decisions for web traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network Rule
Why it's wrong here
Network rules in Azure Firewall operate at Layer 3/4 and match traffic based solely on source and destination IP addresses, ports, and protocol—they contain no concept of a fully qualified domain name. To restrict outbound egress to *.microsoft.com, you would need to resolve the FQDN to IPs, which is impractical because addresses can change and wildcard domain sets are not enumerable statically. Thus, a network rule cannot enforce the required domain-scoped allowlist.
- ✓
Application Rule
Why this is correct
Application rules in Azure Firewall are purpose-built for outbound and east-west traffic filtering based on FQDNs, supporting wildcard patterns such as *.microsoft.com to match any subdomain. They work by inspecting the Host header of HTTP sessions or the SNI/TLS extension of encrypted connections, and with DNS proxy enabled they resolve FQDNs to current IPs before forwarding. This allows the firewall to enforce a precise allowlist of target domains, making it the correct rule type for this requirement.
- ✗
NAT Rule
Why it's wrong here
NAT rules in Azure Firewall are designed to translate the destination IP and port of inbound traffic, typically to expose internal services to the internet, rather than to inspect or allow outbound connections. They change the destination address of packets arriving at the firewall's public IP, and they do not evaluate the domain name (FQDN) of outbound requests. Consequently, a NAT rule cannot be used to restrict which external domains a VM is allowed to reach.
- ✗
DNAT Rule
Why it's wrong here
A DNAT rule is a specific NAT rule type in Azure Firewall used for inbound destination network address translation, mapping a public IP/port to an internal private IP/port. It applies to traffic whose destination is the firewall itself, not to traffic that the firewall is routing outbound, so it has no role in filtering egress traffic. Moreover, DNAT rules do not inspect application-layer parameters like FQDNs, so they cannot restrict outbound connections to *.microsoft.com.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.