AZ-500 Secure networking Practice Question
A company has an Azure virtual network with multiple subnets hosting different tiers of an application. The security team requires inspection of all traffic between subnets for malicious patterns and the ability to allow or deny traffic based on fully qualified domain names (FQDNs). Which Azure networking service should they implement?
⚠ Common exam trap
Watch out — candidates often confuse NSGs with Azure Firewall, assuming NSGs can filter based on FQDNs or inspect traffic for malicious patterns, but NSGs lack Layer 7 inspection and FQDN support, which are exclusive to Azure Firewall in this context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Firewall
Azure Firewall is a managed, cloud-based network security service that provides full Layer 3–7 inspection and can filter traffic based on FQDNs in network and application rules. It can inspect all traffic between subnets in a virtual network (via forced tunneling or routing) and supports threat intelligence-based filtering for malicious patterns, making it the correct choice for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Network Security Group (NSG)
Why it's wrong here
NSGs provide distributed stateful filtering at the subnet or NIC level, using Layer-3/4 rules based on source/destination IP, port, and protocol. They cannot inspect application-layer content or use fully qualified domain names (FQDNs), and they lack centralized logging, TLS inspection, and built-in threat intelligence. While NSGs can filter inter-subnet traffic, that limited feature set does not meet the FQDN-based and advanced inspection requirements.
- ✓
Azure Firewall
Why this is correct
Azure Firewall is a fully managed, stateful platform service that enforces centralized network and application rules, including FQDN-based Layer-7 filtering, TLS inspection, and threat-intelligence-based filtering. When deployed with user-defined routes (UDRs) and forced tunneling, it can inspect and control traffic flowing between subnets, providing a unified audit and management point. Its combination of network and application rules makes it the correct choice for this scenario.
- ✗
Azure Application Gateway
Why it's wrong here
Azure Application Gateway is a Layer-7 load balancer designed for HTTP/HTTPS web workloads, offering features such as URL path-based routing, SSL offload, and a web application firewall (WAF). It is not a general-purpose inter-subnet traffic filter; it only handles traffic destined to web endpoints and lacks the ability to insert policy for arbitrary IP/port/protocol communications between subnets. Therefore, using it for routing and inspection of general east-west traffic is inappropriate.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway is used to establish encrypted IPsec/IKE tunnels between an on-premises network and Azure, or between virtual networks, for connectivity. It does not sit in the data path for traffic moving between subnets within the same virtual network, so it cannot inspect or filter that traffic. Its purpose is connectivity, not security policy enforcement, making it unsuitable for the stated requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.