AZ-500 Secure networking Practice Question
A company has an Azure virtual network with multiple subnets hosting different application tiers. They need to inspect and filter all outbound traffic from VMs to the internet, and they must be able to allow or deny traffic based on fully qualified domain names (FQDNs). Which Azure networking service should they deploy?
⚠ Common exam trap
Watch out — candidates often confuse Network Security Groups (NSGs) with Azure Firewall, assuming NSGs can filter by FQDN because they support service tags, but service tags are IP-based and do not allow granular FQDN-level control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Firewall.
Azure Firewall is a managed, cloud-based network security service that can inspect and filter outbound traffic from Azure virtual networks to the internet. It supports application rules based on fully qualified domain names (FQDNs), allowing or denying traffic by FQDN, which directly meets the requirement. Unlike simpler filtering options, Azure Firewall provides stateful inspection and integrates with Azure Monitor for logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Firewall.
Why this is correct
Azure Firewall is a managed, cloud-native network security service that enforces application-layer rules based on FQDN. Its application rule collection can allow or deny outbound traffic to specific domain names (e.g., *.windowsupdate.com) independently of IP address, which is critical because many cloud services resolve to changing IPs. Azure Firewall also supports network rules, threat intelligence, and is centrally deployed to inspect all egress traffic, making it the correct choice for application-level outbound filtering.
- ✗
Network Security Groups (NSGs).
Why it's wrong here
Network Security Groups (NSGs) are stateful packet filters that operate at the TCP/UDP layer, inspecting source/destination IPs, ports, and protocols. They do not perform payload inspection or parse application-layer headers, so they cannot distinguish traffic by FQDN—only by individual IP addresses or CIDR ranges. Since destinations like CDNs or SaaS endpoints often use dozens of dynamic IPs, NSGs cannot reliably enforce domain-based allow lists, which is exactly why they fail for this requirement.
- ✗
Azure Application Gateway.
Why it's wrong here
Azure Application Gateway is a layer-7 load balancer designed to route inbound HTTP(S) traffic to backend pools based on URL path, host, or other routing rules. It sits in front of web applications to provide SSL termination and a Web Application Firewall (WAF), but it is not placed in the outbound egress path from virtual machines to the internet. It has no concept of governing which external FQDNs a workload may reach, so it is irrelevant for controlling outbound application-level access.
- ✗
Azure VPN Gateway.
Why it's wrong here
Azure VPN Gateway is a tunnel-termination service that establishes encrypted IPsec/IKE connections between on-premises networks and Azure, or between VNets. Its purpose is confidentiality and integrity of traffic in transit, not inspection or policy enforcement—it forwards packets after decrypting them without applying any allow/deny rules based on FQDN or application signature. Even if every packet traversed a VPN tunnel, the gateway would not filter egress traffic, so it cannot satisfy the requirement for application-level filtering.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.