Courseiva
Secure networking →hardMultiple Select

AZ-500 Secure networking Practice Question

A public web application should be protected from OWASP-style attacks and network-layer DDoS attacks. Which two Azure services are most relevant?

⚠ Common exam trap

Test-takers frequently confuse Azure Automation State Configuration (a DevOps tool) with a security service, or assume Azure Files premium tier offers built-in attack protection, when in fact only WAF and DDoS Protection directly address the specified OWASP and DDoS threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application Gateway WAF or Azure Front Door WAF

Both Azure Application Gateway WAF and Azure Front Door WAF provide managed rule sets (e.g., OWASP Core Rule Set 3.2) that protect against common web vulnerabilities such as SQL injection and cross-site scripting. Option C is correct because Azure DDoS Protection, when enabled on the virtual network hosting the application, mitigates network-layer DDoS attacks (e.g., SYN floods, UDP floods) by leveraging Azure's global infrastructure to absorb and scrub attack traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application Gateway WAF or Azure Front Door WAF

    Why this is correct

    Application Gateway WAF and Azure Front Door WAF are layer-7 web application firewall services that inspect inbound HTTP/HTTPS traffic and apply managed rule sets designed explicitly around the OWASP Top 10, including SQL injection and cross-site scripting. Both can operate in detection or prevention mode, support custom rules and rate limiting, and integrate with Azure Security Center, making them the direct, primary solution for OWASP protection on a public web app.

  • ✗

    Azure Automation State Configuration

    Why it's wrong here

    Azure Automation State Configuration (DSC) is an infrastructure configuration management feature that defines and maintains the desired state of VMs—such as installing packages, managing files, and enforcing registry settings. It does not inspect application traffic or parse HTTP requests, so it cannot block OWASP Top 10 exploits or act as an inline security boundary, making it inapplicable to this web application protection requirement.

  • ✓

    Azure DDoS Protection on the virtual network where applicable

    Why this is correct

    Azure DDoS Protection, applied to a virtual network, protects the web application's public IP addresses from large-scale volumetric, protocol, and transport-layer attacks, which is a legitimate part of an end-to-end defense-in-depth architecture. It does not provide application-layer parsing required to detect OWASP Top 10 payloads, so it should be paired with a layer-7 WAF; in that layered implementation it is correct for the stated requirement of protecting a public web application from both infrastructure and application-layer threats.

  • ✗

    Azure Files premium tier

    Why it's wrong here

    Azure Files premium tier is a high-performance managed file share offering designed for throughput-sensitive workloads, with no HTTP inspection or request filtering capabilities. Its security features are limited to shared access signatures, encryption at rest/in transit, and identity-based access controls, none of which mitigate OWASP Top 10 web application vulnerabilities such as SQL injection, XSS, or broken authentication.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.