Courseiva

AZ-500 · domain

Secure networking

Secure networking is 24% of AZ-500 and covers designing and configuring network controls that protect Azure workloads. Expect scenario items on NSG and Azure Firewall rules, service endpoints versus private endpoints, VNet peering and routing, DDoS Protection, and Bastion or VPN access, plus interpreting effective security rules and diagnosing connectivity failures.

151 questions50 easy67 medium34 hard

Focused practice

Practice Secure networking questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Secure networking

You must configure NSGs, Azure Firewall, private endpoints, VNet peering, DDoS Protection, and Bastion to secure traffic. Get rule evaluation order right: NSG priority, Azure Firewall DNAT/network/application rules, and effective routes.

Configuring NSG security rules, priorities, and application security groups for subnet traffic

Choosing Azure Firewall, NSG, or WAF for filtering and inspecting network flows

Implementing Private Link and private endpoints versus service endpoints for PaaS access

Securing remote administration with Azure Bastion, VPN Gateway, and Just-in-Time VM access

Watch out for

Common Secure networking exam traps

  • ▸Assuming service endpoints provide private IP connectivity; they only restrict access over the Azure backbone while traffic still uses public endpoints.
  • ▸Forgetting that NSG rules are stateful and that a lower-priority number wins, so deny rules can silently override intended allow rules.
  • ▸Believing Azure Firewall replaces NSGs; both are needed since NSGs filter at subnet/NIC level and Firewall handles centralized egress and FQDN filtering.

Question index

All Secure networking questions (151)

Click any question to see the full explanation, or start a practice session above.

1

You need to restrict access to an Azure Storage account so that only traffic from a specific virtual network is allowed. What should you configure?

Easy
2

A company has several critical applications deployed in an Azure virtual network. The security team wants to protect the virtual network against Distributed Denial-of-Service (DDoS) attacks by enabling automatic attack mitigation, adaptive tuning, and access to DDoS Rapid Response Support. Which DDoS Protection tier should they enable for the virtual network?

Easy
3

You need to securely connect two Azure virtual networks in the same region to allow VM-to-VM communication using private IP addresses. The solution must minimize latency and administrative overhead. What should you use?

Easy
4

You manage a multi-tier application in Azure with a web tier, application tier, and database tier. The web tier must be accessible from the internet, but the application and database tiers must only be accessible from the web tier. Which Azure networking feature should you use to isolate the tiers?

Easy
5

You need to securely connect an on-premises network to an Azure virtual network. The connection must use the internet and provide authenticated and encrypted communication. Which Azure service should you use?

Easy
6

A company has an Azure virtual network with two subnets: App and Data. The App subnet hosts web servers, and the Data subnet hosts SQL databases. Security policy requires that only HTTPS traffic from the App subnet is allowed to the Data subnet, and all other inbound traffic to the Data subnet must be blocked. The solution must use a single network security group (NSG) associated to the Data subnet. Which NSG inbound rule configuration meets the requirement?

Medium
7

A company is deploying Azure Bastion to provide secure RDP/SSH access to VMs in a virtual network. The security requirement is that all administrative access must be logged and audited. What additional configuration is needed to meet this requirement?

Medium
8

A company runs a public-facing web application on Azure App Service in the West US region. They want to protect against network-layer (Layer 3/4) DDoS attacks and have a single web application. Which Azure DDoS Protection tier should they use?

Medium
9

A company has an Azure virtual network with multiple subnets hosting different tiers of an application. The security team requires inspection of all traffic between subnets for malicious patterns and the ability to allow or deny traffic based on fully qualified domain names (FQDNs). Which Azure networking service should they implement?

Easy
10

You need to block inbound traffic from the internet to a specific subnet except for TCP port 443. Which Azure service should you use?

Easy
11

Refer to the exhibit. You have a VNet with two subnets, each with a different NSG. Both NSGs have default rules. What is the default connectivity between VMs in subnetA and subnetB?

Easy
12

You are designing a secure network architecture for a three-tier application. The web tier must be accessible from the internet, while the application and database tiers must only be accessible from the web tier. Which Azure service should you use to isolate the tiers most securely?

Easy
13

You configure Azure Bastion to allow secure RDP access to VMs in a VNet. However, users report that they cannot connect to a specific VM, while other VMs in the same VNet are accessible. The VM is running and has a public IP. What is the most likely cause?

Medium
14

A company has an Azure virtual network with a subnet that hosts a web application. They want to allow inbound HTTPS traffic from any source on the internet (0.0.0.0/0) and block all other inbound traffic. They associate a network security group (NSG) with the subnet. What is the minimum number of inbound security rules required to achieve this?

Medium
15

You need to secure traffic between two VNets in different Azure regions. The VNets contain virtual machines that must communicate over private IP addresses. Which Azure service should you use?

Easy
16

An Application Gateway WAF blocks legitimate requests because a managed rule detects a known false positive. The team wants to keep the rule set enabled. What should they configure?

Hard
17

A company has a hub-and-spoke network topology in Azure. The hub virtual network contains an Azure Firewall and a VPN gateway. Spoke virtual networks are peered to the hub. The security team wants to ensure that all outbound internet traffic from VMs in the spokes flows through the Azure Firewall. What should be configured?

Medium
18

You need to securely connect an on-premises network to Azure over the internet with encrypted traffic. The connection must be site-to-site and use IPsec. Which Azure service should you use?

Easy
19

A company has a virtual network with a subnet hosting Azure VMs. They want to restrict all inbound traffic to only allow HTTPS (port 443) from the internet, but also allow SSH (port 22) only from a specific management IP address range (e.g., 203.0.113.0/24). Which Azure service should they use to achieve this filtering?

Easy
20

You are troubleshooting connectivity between two Azure VMs in the same virtual network. VM1 can ping VM2, but VM1's application cannot connect to VM2's application on port 8080. Both VMs have NSGs that allow inbound traffic on port 8080. What is the most likely cause?

Hard
21

You have an Azure virtual machine that hosts a custom web application. You need to restrict inbound internet traffic to only HTTPS (port 443) from any source. Which Azure resource should you configure?

Easy
22

A company has an Azure virtual network with a subnet hosting web servers. The security policy requires that all inbound HTTP traffic must be sourced from a specific IP address range (203.0.113.0/24). All other inbound traffic must be denied. The subnet is associated with a network security group (NSG). Which set of inbound rules should they configure?

Medium
23

A company has an Azure virtual network with a subnet that hosts a web application. They need to allow inbound HTTP (port 80) and HTTPS (port 443) traffic from a specific source IP range (203.0.113.0/24) to the web servers. Additionally, they need to allow inbound RDP (port 3389) traffic from a management subnet (10.0.1.0/24). They want to block all other inbound traffic. They are using a network security group (NSG) associated with the subnet. What is the minimum number of inbound security rules required?

Medium
24

You are a security engineer for Contoso. The company uses Azure Firewall for all inbound and outbound traffic. To prevent misconfiguration, you assign the Azure Policy shown in the exhibit at the management group scope. After assignment, a network administrator reports that they cannot create a new subnet in an existing virtual network. The subnet creation fails with a 'deny' policy error. You need to allow subnet creation while still blocking NSG rule changes. What should you do?

Hard
25

You are a security engineer at Northwind Traders. The company has an Azure subscription with a virtual network named VNet1. You need to ensure that all outbound internet traffic from VNet1 is inspected by a central security appliance before leaving the network. You also need to log all traffic for auditing. The solution must minimize administrative effort and support scaling. What should you deploy?

Medium
26

Which THREE of the following are required to enable network traffic flow between two peered Azure virtual networks in different Azure regions?

Hard
27

A company deploys multiple Azure virtual machines across several subnets in a virtual network. The VMs are grouped by application tiers: web, application, and database. The security team wants to apply network security group (NSG) rules that target all VMs in a specific tier, and they need a way to easily add or remove VMs from these groups without updating NSG rules. Which Azure feature should they use to define these logical VM groups?

Easy
28

You are the security engineer for a financial services company that has multiple Azure subscriptions. The company uses Azure Virtual WAN with a secured hub containing Azure Firewall. Recently, the compliance team identified that traffic between two spoke virtual networks (SpokeA and SpokeB) is bypassing the firewall. Investigation shows that SpokeA and SpokeB are directly peered and have not been routed through the hub. The requirement is that all inter-spoke traffic must be inspected by Azure Firewall. You need to enforce this without disrupting existing applications. Also, the company uses Azure Firewall Manager for policy management and wants to use Azure Policy to prevent future direct peering. What should you do first?

Hard
29

Which TWO of the following are supported ways to connect an on-premises network to Azure?

Easy
30

A company has an Azure virtual network with a subnet that hosts a public web application. They want to allow inbound HTTPS traffic (port 443) only from the source IP range 203.0.113.0/24, and block all other inbound traffic. They associate a network security group (NSG) with the subnet. What is the minimum number of inbound security rules required in the NSG to achieve this?

Easy
31

A company uses Azure Bastion to provide secure RDP and SSH access to Azure VMs without public IPs. Recently, a security audit recommended logging all connections to Bastion. What should you enable?

Medium
32

A storage account should be reachable only from a specific subnet over the Microsoft backbone, while keeping the public endpoint firewall restricted. Which feature should be used?

Medium
33

You have an Azure virtual machine that hosts a web application. You need to allow inbound HTTP (80) and HTTPS (443) traffic from the internet to this VM only. You also need to allow outbound traffic to the internet from the VM. You want to use a managed Azure service with minimal configuration. What should you use?

Easy
34

Your organization has deployed Azure Front Door Premium with Web Application Firewall (WAF) policy in front of an Azure App Service. You need to ensure that only traffic from Azure Front Door is allowed to reach the App Service, and all other traffic is blocked. Which configuration should you implement?

Hard
35

Your organization has a hybrid network with an Azure VPN gateway connecting to an on-premises site. You need to ensure that traffic between Azure and on-premises is encrypted and authenticated. Which protocol should the VPN gateway use?

Medium
36

A security administrator is troubleshooting network connectivity to an Azure virtual machine. The VM is behind a network security group (NSG) that has a deny-all inbound rule as the default. The administrator wants to quickly verify whether a specific TCP packet on port 3389 from their client IP (203.0.113.50) would be allowed or blocked by the NSG. Which Azure Network Watcher tool should they use?

Easy
37

A company has deployed Azure Firewall in a hub virtual network with forced tunneling enabled. Spoke virtual networks are peered to the hub. The security team reports that outbound traffic from the spoke VMs is bypassing the firewall. What is the most likely reason?

Hard
38

Your company uses Azure Firewall to protect a virtual network. The security team needs to allow outbound HTTPS traffic from a specific subnet to a set of FQDNs, such as '*.contoso.com', while blocking all other outbound traffic. Which type of Azure Firewall rule should they configure?

Easy
39

You need to secure traffic between an on-premises network and Azure using a VPN connection. Which TWO configurations are required?

Easy
40

A company has two Azure virtual networks in different Azure regions that need to communicate with each other. The security policy mandates that all inter-region traffic must be encrypted over the public internet. Which connectivity solution should the company implement to meet this requirement?

Medium
41

Which TWO components are required to implement a secure hybrid network that connects on-premises to Azure using ExpressRoute? (Choose two.)

Hard
42

Your company uses Azure Firewall Premium with TLS inspection to filter outbound traffic from Azure VMs. Users report that some websites are not loading. You have configured the firewall to inspect traffic to *.microsoft.com. What is the most likely cause of the issue?

Hard
43

You are a security engineer at Adventure Works. The company has an Azure Kubernetes Service (AKS) cluster that uses the Azure CNI network plugin. The cluster's pods must access an Azure SQL Database securely without traversing the public internet. You need to configure private connectivity from the AKS cluster to the Azure SQL server. What should you implement?

Hard
44

You need to provide secure remote access to Azure virtual machines for developers without exposing public IP addresses. The solution must authenticate users via Microsoft Entra ID and support multifactor authentication. Which service should you use?

Easy
45

You are designing network security for a three-tier application. You need to isolate each tier (web, application, data) and control traffic between them. Which TWO Azure services should you use to achieve this? (Choose two.)

Medium
46

You are designing a secure network architecture for a multi-region application. You need to ensure that traffic between virtual networks in different Azure regions is encrypted and uses the Microsoft backbone network, and you must minimize latency. Which TWO configurations should you implement?

Hard
47

You are deploying a web application in Azure that must be accessible only from your corporate network via HTTPS. You have an Azure Application Gateway with a Web Application Firewall (WAF) policy. Your corporate network uses public IP addresses from a specific range. Which configuration should you use to restrict access?

Medium
48

Drag and drop the steps to configure Azure AD Conditional Access policy to require MFA for all users into the correct order.

Medium
49

Refer to the exhibit. You have an Azure Application Gateway WAF policy with the above JSON configuration. A user from IP address 10.1.2.3 reports they cannot access the web application. What is the most likely cause?

Hard
50

Which TWO are valid connection methods for Azure VPN Gateway? (Choose two.)

Easy
51

A company has an Azure virtual network with subnets SubnetA and SubnetB. They deploy a network virtual appliance (NVA) in a subnet called NVA_Subnet. They want all traffic between SubnetA and SubnetB to be routed through the NVA for inspection. What is the minimum number of route tables and routes required?

Easy
52

Your organization needs to securely connect an on-premises data center to Azure for disaster recovery. The connection must be encrypted and use the public internet. Which Azure service should you use?

Easy
53

A company deploys Azure Firewall to inspect and control outbound traffic from a virtual network. The security team wants to allow outbound HTTPS traffic only to specific FQDNs such as *.microsoft.com and *.windowsupdate.com, while blocking all other outbound internet access. Which type of rule should they configure in Azure Firewall to achieve this filtering?

Easy
54

You are a security engineer for Adventure Works. The company has an Azure subscription with a virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 hosts an Azure App Service Environment (ASE) and several Azure virtual machines. You need to inspect all traffic between Subnet1 and the internet for malicious content and generate alerts for suspicious activity. You also need to ensure that the solution can decrypt and inspect HTTPS traffic. What should you do?

Hard
55

Drag and drop the steps to create an Azure Key Vault firewall rule to allow access from a specific virtual network into the correct order.

Medium
56

You are a security engineer at Adatum. The company has an Azure subscription with a virtual network named VNet1 that contains an Azure Firewall in a subnet named AzureFirewallSubnet. You need to ensure that all outbound traffic from a subnet named AppSubnet is inspected by the firewall, including traffic to other subnets in VNet1 and to the internet. What should you configure?

Medium
57

You have an Azure Web Application Firewall (WAF) policy associated with an Azure Front Door instance. You want to block requests from a specific country (e.g., Country X) unless the request includes a valid API key. How should you configure this?

Medium
58

A company wants to deploy an Azure VPN Gateway in active-active mode to ensure high availability for their site-to-site VPN connection. They have two on-premises VPN devices, each with a distinct public IP address. What is the minimum configuration required for the Azure VPN Gateway to utilize both on-premises devices?

Hard
59

You need to allow a specific IP address (203.0.113.5) to access an Azure Storage account over the internet. All other internet traffic must be denied. You have enabled the storage account firewall. What should you configure?

Easy
60

Which TWO Azure services can be used to filter inbound internet traffic to a virtual network? (Choose two.)

Medium
61

A company has two application tiers: web servers and application servers. They want to allow traffic from the web servers to the application servers on port 8080, but only for a specific set of web servers. They have deployed the web servers in an Availability Set and want to use a single NSG rule to allow traffic from any web server that is part of that application tier. Which component should they use?

Medium
62

You are a security engineer at Litware. The company has an Azure virtual network named VNet1 with a subnet named Subnet1 that hosts several virtual machines. You need to restrict outbound internet access from Subnet1 to only allow traffic to specific FQDNs, such as *.microsoft.com and *.azure.com, while blocking all other outbound internet traffic. You also need to log allowed and denied traffic. Which two actions should you perform? (Choose two.)

Medium
63

You are a security engineer for Fabrikam. The company has an Azure virtual network named VNet1 that contains a subnet named Subnet1 with several VMs. You need to ensure that all traffic from Subnet1 to the internet is inspected by Azure Firewall, and that the VMs can resolve external DNS names using Azure-provided DNS. The firewall is deployed in a subnet named AzureFirewallSubnet. Which two actions should you perform? (Choose two.)

Hard
64

Which THREE are best practices for securing network traffic in Azure? (Choose three.)

Hard
65

You are designing network security for a hybrid application that uses Azure Front Door and Azure Application Gateway. The application must block malicious requests at the edge before they reach the backend. You need to implement Web Application Firewall (WAF) protection with the lowest latency and the ability to inspect traffic at the application layer. Which solution should you use?

Medium
66

A company has two Azure virtual networks, VNet-A and VNet-B, connected via VNet peering. They want all traffic between the VNets to be inspected by a network virtual appliance (NVA) deployed in a subnet in VNet-A. They have configured a user-defined route (UDR) on the subnet in VNet-B that points the destination address space of VNet-A to the private IP of the NVA. However, traffic between the VNets is still not passing through the NVA. What is the most likely cause?

Hard
67

Which TWO actions should you take to secure a virtual network in Azure? (Choose two.)

Medium
68

A company deploys Azure virtual machines in a virtual network. A security policy requires that only Remote Desktop Protocol (RDP) traffic from the corporate VPN's public IP address (203.0.113.0/26) is allowed. All other inbound RDP traffic must be denied. Which configuration should be applied to the network security group (NSG) associated with the VM subnet?

Easy
69

A company is designing a hub-spoke network topology with Azure Firewall in the hub virtual network. Spoke virtual networks are peered to the hub. They want to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP address as the next hop. However, traffic is still bypassing the firewall. What is the most likely cause?

Medium
70

A company uses Azure Firewall to filter outbound traffic. They want to ensure that all DNS queries from virtual machines in a spoke VNet are routed through the Azure Firewall for logging and inspection. They have already configured the firewall to use a custom DNS server. Which additional Azure Firewall feature must be enabled to ensure that the VMs use the firewall as a DNS proxy?

Medium
71

Your company uses Azure Firewall Premium. You need to inspect outbound traffic for malware using signature-based detection. Which feature should you enable?

Medium
72

You are analyzing network traffic patterns. You have configured NSG flow logs with Traffic Analytics as shown in the exhibit. You need to identify which virtual machines are communicating with a specific malicious IP address. Which tool should you use to query the flow log data?

Easy
73

Your company deploys a web application in an Azure App Service that needs to securely connect to an Azure SQL Database. You want to avoid exposing the database to the public internet. What is the recommended approach?

Medium
74

You are configuring a site-to-site VPN connection between your on-premises network and Azure. You need to ensure that traffic between the networks is encrypted and authenticated. Which Azure service should you use?

Medium
75

You need to provide secure remote access to Azure virtual machines for administrators without exposing them to the public internet. The solution must use a single entry point and support Azure Active Directory (now Microsoft Entra ID) authentication. Which Azure service should you use?

Easy
76

You have an Azure subscription with multiple virtual networks. You need to centrally manage and enforce security policies for all outbound traffic from virtual machines to the internet. The solution must be able to inspect traffic and log all connections. What should you deploy?

Medium
77

A company has Azure virtual machines that need to download updates from specific external websites (e.g., *.microsoft.com and *.windowsupdate.com). The security team wants to centrally manage and allow outbound HTTPS traffic only to these FQDNs, while blocking all other outbound internet access. Which Azure networking service should they deploy to achieve this?

Easy
78

A company has a hub-spoke network topology in Azure. They need to inspect and filter all traffic flowing between spoke virtual networks for malicious content and require that the inspection is stateful. Which Azure-native service should they deploy in the hub virtual network to meet this requirement?

Hard
79

You need to secure outbound traffic from an Azure virtual network to the internet. All outbound traffic must be inspected by a firewall and logged. You also need to ensure that traffic to known malicious IP addresses is blocked. Which solution should you implement?

Medium
80

You are an Azure security engineer. Your team has assigned the Azure Policy shown in the exhibit. A developer creates a new virtual network with a subnet that does not have a Network Security Group (NSG) associated. What will happen when the policy is evaluated?

Medium
81

Refer to the exhibit. You are reviewing an NSG rule configuration for a subnet. The source subnet is 10.0.0.0/24 and the destination subnet is 10.0.1.0/24. What is the effect of this rule?

Medium
82

Your company has an Azure subscription with several VNets. You deploy Azure Firewall in a hub VNet. You need to ensure that all traffic from spoke VNets to the internet goes through the firewall. What should you configure?

Medium
83

You are designing a network security solution for a multi-tier application in Azure. The web tier must be accessible from the internet, the application tier only from the web tier, and the database tier only from the application tier. All tiers are in different subnets of the same VNet. What is the minimum configuration?

Medium
84

A company uses Azure Front Door (AFD) with WAF policy in front of a web application. The security team notices that some requests from a specific IP range are being blocked incorrectly. The WAF policy uses custom rules. The team wants to allow a specific IP range while still having the WAF inspect other traffic. What is the most efficient way to configure this?

Hard
85

A company deploys Azure Firewall in a hub VNet to inspect all outbound traffic from a spoke VNet. They enable VNet peering between the hub and spoke. They create a route table with a default route (0.0.0.0/0) pointing to the firewall's private IP as the next hop, and associate it with the spoke subnets. However, outbound traffic from the spoke subnets is still going directly to the internet, bypassing the firewall. What is the most likely cause?

Medium
86

You are designing a secure network for an e-commerce application in Azure. The application consists of web servers, application servers, and database servers. You need to ensure that inbound traffic is filtered at multiple layers. Which THREE Azure services should you use to implement defense in depth for network security?

Medium
87

Your organization uses Azure Virtual WAN. You need to secure traffic between a spoke VNet and an on-premises site that connects via a Virtual WAN VPN gateway. What is the best way to inspect traffic?

Medium
88

A company has an Azure SQL Database with a private endpoint connection. The database is accessed from on-premises via ExpressRoute and from other Azure virtual networks (VNets) via VNet peering. The security team wants to ensure that all queries from both on-premises and peered VNets go through the private endpoint and NEVER use the public endpoint, even as a fallback. Which additional configuration is required to enforce this?

Hard
89

A company has established a site-to-site VPN connection between its on-premises network and an Azure virtual network using an Azure VPN gateway. The security team wants to confirm that all traffic crossing the VPN tunnel is encrypted. Which protocol does the Azure VPN gateway use to encrypt the data?

Easy
90

You have an Azure Kubernetes Service (AKS) cluster that needs to restrict egress traffic to specific Azure services (e.g., Azure Container Registry, Azure Monitor). You want a managed solution that allows you to define FQDN-based rules. Which Azure service should you use?

Hard
91

You need to monitor network traffic to detect anomalies and potential security threats. Which THREE Azure services can you use to achieve this? (Choose three.)

Hard
92

You are configuring Azure DDoS Network Protection for your VNet. Which TWO benefits does enabling DDoS Protection Standard provide?

Easy
93

You are a security engineer at Fabrikam. The company has an Azure virtual network that contains a subnet named WebSubnet with a network security group (NSG) named NSG1. You need to ensure that inbound HTTP traffic from the internet is allowed to the web servers in WebSubnet, but only when the traffic originates from a specific set of public IP addresses used by a partner company. The partner's IP addresses are 203.0.113.0/24 and 198.51.100.10. What should you configure in NSG1?

Hard
94

You need to block outbound internet access from all VMs in a VNet except for specific allowed destinations (e.g., Microsoft updates). You cannot use a third-party NVA. Which Azure service should you use to meet this requirement?

Easy
95

You have an Azure virtual machine that hosts a web application on port 443 and a management interface on port 8443. You need to allow inbound HTTPS traffic from the internet to port 443, and allow inbound traffic on port 8443 only from the company's office public IP range (203.0.113.0/24). You want to use a managed service that provides basic DDoS protection at no additional cost. What should you use?

Easy
96

You have an Azure subscription with a virtual network (VNet1) that hosts a SQL Managed Instance. You need to connect from an on-premises application to the SQL Managed Instance using a private IP address, with minimal latency and without traversing the public internet. The on-premises network has a high-speed ExpressRoute connection to Microsoft. What should you configure?

Medium
97

You are designing a hub-and-spoke network topology with Azure Firewall in the hub VNet. Which TWO components are essential for routing traffic from spoke VNets through the firewall? (Choose two.)

Easy
98

You are troubleshooting connectivity issues from an Azure VM to an on-premises server. The VM is in a VNet that uses a custom DNS server. The on-premises network is connected via ExpressRoute. You can ping the on-premises server by IP address but not by name. What is the most likely cause?

Hard
99

A company has an Azure virtual network with two subnets: Frontend and Backend. They deploy a network virtual appliance (NVA) in a subnet named NVA_Subnet. They want to route all traffic from the Frontend subnet to the Backend subnet through the NVA for inspection. What is the minimum number of route tables required to achieve this traffic steering?

Easy
100

A company has a hub-spoke network topology in Azure. The hub virtual network contains an Azure Firewall. Spoke virtual networks are peered to the hub. The security team wants to inspect all traffic between virtual machines in different spoke virtual networks. What is the minimum configuration required?

Medium
101

You are designing network security for a multi-tier application. The web tier must be accessible from the internet, but the database tier must only be accessible from the web tier. Both tiers are in the same virtual network. Which Azure service should you use to restrict traffic between the tiers?

Easy
102

A company uses Azure Firewall to inspect traffic between a spoke VNet hosting a web application and a hub VNet hosting a SQL database. The web application fails to connect to the database after a recent network topology change. You verify that the Azure Firewall rules allow the traffic. Which Azure Network Watcher feature should you use to identify the root cause?

Medium
103

A company plans to use Azure Private Endpoint to securely connect to an Azure SQL Database from an on-premises network via ExpressRoute. The private endpoint is deployed in a hub virtual network. The on-premises network is connected to the hub via ExpressRoute. What additional configuration is needed to ensure on-premises clients can resolve the private endpoint's DNS name?

Hard
104

A company has a hub-spoke network topology in Azure. The spoke virtual networks contain Azure virtual machines that need to access the internet. The security team requires that all outbound internet traffic from the spoke VMs passes through the Azure Firewall deployed in the hub virtual network for inspection and logging. Which configuration should be implemented to ensure this traffic is routed through the firewall?

Medium
105

You are securing an Azure Kubernetes Service (AKS) cluster. You need to restrict network traffic between pods and to external services using Azure network policies. Which three of the following options are valid considerations or steps? (Choose three.)

Medium
106

You have an Azure application that uses a private endpoint for Azure SQL Database. Users report intermittent connectivity failures. You need to diagnose whether the private endpoint DNS resolution is working correctly. Which tool should you use?

Hard
107

A company has an Azure virtual network with a subnet that hosts a web application. The security team wants to allow inbound HTTPS traffic (port 443) from the internet to the web servers, but block all other inbound traffic. They have a network security group (NSG) associated with the subnet. What is the minimal set of inbound rules required?

Easy
108

You need to design a network security solution for a hub-spoke topology. The hub contains Azure Firewall and Azure Bastion. Spoke VNets contain application workloads. You need to ensure that all traffic from the spokes to the internet is routed through the Azure Firewall. What should you configure?

Medium
109

A company has an Azure virtual network with a single subnet that hosts web servers. The security team needs to allow inbound HTTPS traffic from the internet to the web servers, but block all other inbound traffic. They want to use a single Azure resource to accomplish this at the subnet level. Which resource should they configure?

Easy
110

A company has a hub-spoke network topology with Azure Firewall deployed in the hub virtual network. Spoke virtual networks are peered to the hub. The security team needs to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall private IP address. However, traffic from spoke VMs is still bypassing the firewall and going directly to the internet. What is the most likely reason?

Hard
111

A company has an Azure virtual network with multiple subnets. They want to centrally inspect and log all outbound traffic to the internet. They also need to allow or deny traffic based on domain names (FQDNs). Which Azure resource should they deploy?

Medium
112

You are designing a network security solution for a multi-tier application. The web tier must be accessible from the internet, but the application and database tiers must be isolated. Which TWO configurations should you implement?

Medium
113

You have an Azure subscription with multiple VNets connected via VNet peering. You need to audit all network traffic between two specific VNets for compliance. The solution must capture traffic metadata (source/destination IP, ports, protocol) without affecting performance. What should you use?

Hard
114

Your company has an Azure subscription with a hub-spoke network topology. The hub contains an Azure Firewall and a VPN gateway for on-premises connectivity. The spoke virtual network hosts a critical application. You need to ensure that all outbound traffic from the spoke to the internet and on-premises networks flows through the Azure Firewall. You configure a user-defined route (UDR) on the spoke subnet with the default route (0.0.0.0/0) pointing to the Azure Firewall private IP. However, traffic to on-premises still bypasses the firewall. What is the most likely cause?

Hard
115

You are configuring Azure Private Link for a SQL Database. You want to ensure that all traffic from your virtual network to the SQL Database stays within the Microsoft Azure backbone network. What is the primary benefit of using Azure Private Link over a service endpoint?

Easy
116

You need to restrict access to a web app hosted on Azure App Service so that only traffic from a specific virtual network (VNet) is allowed. Which Azure service should you configure?

Easy
117

A company has a virtual network in Azure with a subnet that hosts a web application. They want to allow inbound HTTPS traffic only from a specific source IP range (198.51.100.0/24). They are using Network Security Groups (NSGs) associated with the subnet. What is the minimal set of inbound security rules required?

Easy
118

You have an Azure Application Gateway v2 with WAF policy in prevention mode to protect a web app. Users report that legitimate requests are being blocked. You review the WAF logs and see many false positives. You need to resolve this while maintaining security. What should you do?

Medium
119

A company has virtual networks in East US and West US connected via global VNet peering. The security policy requires that all traffic between the peered VNets be encrypted using IPsec. Which action should the company take to meet this requirement?

Hard
120

Refer to the exhibit. You run the PowerShell command above and get the output: Access: Allow, SourceAddressPrefix: *, DestinationAddressPrefix: VirtualNetwork, DestinationPortRange: 22, Protocol: TCP, Priority: 100. A security audit requires that SSH access be restricted to only the management subnet (10.0.1.0/24). What should you do?

Medium
121

A company uses a hub-spoke network topology in Azure. They need to inspect and filter all traffic flowing between spoke virtual networks for security compliance. Which Azure-native service should be deployed in the hub virtual network to achieve this?

Medium
122

You need to distribute incoming internet traffic across multiple Azure virtual machines in the same region. The solution must provide layer 7 load balancing and SSL offloading. Which Azure service should you use?

Easy
123

You are a security engineer for Litware. The company has an Azure virtual network named VNet1 that contains an Azure Bastion host and several VMs. The VMs have public IP addresses, but the security team wants to eliminate all public IP exposure while still allowing administrators to connect via RDP and SSH from the internet. You need to recommend a solution that meets these requirements with the least administrative effort. What should you do?

Hard
124

You need to provide secure remote administration access to Azure virtual machines in a production environment. You want to eliminate public RDP/SSH endpoints and provide just-in-time access. Which Azure service should you use?

Easy
125

Your organization has multiple Azure subscriptions and wants to centrally manage Azure Firewall policies across all subscriptions. What should you use?

Easy
126

A company deploys a web application on Azure VMs behind an Azure Load Balancer (Standard SKU). They want to protect the application from common web attacks like SQL injection and cross-site scripting. Which Azure service should they enable?

Medium
127

Your company has multiple Azure subscriptions managed through Azure Firewall Manager. You need to deploy Azure Firewall policies that apply to all subscriptions in a region. What is the most efficient way to manage this?

Hard
128

Which TWO actions can be taken using Azure Network Watcher?

Easy
129

You are designing network security for a multi-tier application deployed in Azure. The application consists of a front-end web tier, a middle-tier API, and a back-end database. All tiers must be isolated from the internet except the front-end, which must accept HTTPS traffic from the internet. You need to ensure that no traffic can bypass the network security controls. What should you implement?

Medium
130

You need to provide secure remote access to Azure virtual machines without assigning them public IP addresses. Which Azure service should you use?

Easy
131

A company has an Azure virtual network with multiple subnets hosting different application tiers. They need to inspect and filter all outbound traffic from VMs to the internet, and they must be able to allow or deny traffic based on fully qualified domain names (FQDNs). Which Azure networking service should they deploy?

Medium
132

A company runs a global web application on Azure App Service instances deployed in multiple Azure regions. They want to protect the application from common web attacks such as SQL injection and cross-site scripting (XSS) using a centralized set of managed rules that can be automatically updated. They also need to improve performance by terminating traffic at the nearest point of presence (POP) to end users. Which Azure service should they deploy in front of the App Service?

Medium
133

You are designing a network security strategy for a multi-tier application. The web tier must be accessible from the internet, but the application and database tiers must only be accessible from the web tier. Which Azure solution should you use to isolate the tiers?

Medium
134

An organization has deployed Azure Firewall and wants to inspect all outbound traffic from a virtual network (VNet) to the internet. The VNet already contains subnets with workloads. What is the required networking configuration to force traffic through Azure Firewall?

Medium
135

You need to allow inbound HTTP traffic from the internet to a specific VM in a VNet. The VM is in a subnet with an NSG. What is the correct way to configure access?

Medium
136

A company has an Azure virtual network with a subnet that contains virtual machines. They have deployed Azure Firewall in a hub VNet and peered the spoke VNet to the hub. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP as the next hop. However, traffic from the VMs is still going directly to the internet. What is the most likely cause?

Medium
137

Your organization uses Azure Virtual Network Manager (AVNM) to manage network groups. You need to ensure that all virtual networks in a network group are automatically peered with a hub VNet. Which AVNM configuration should you use?

Medium
138

A company uses Azure Front Door to accelerate and secure its public web application. The security team wants to limit the number of requests from a single client IP address to 100 per minute to prevent a single user from overwhelming the backend. Which configuration should they add to the Web Application Firewall (WAF) policy associated with the Front Door?

Medium
139

Your organization has a Microsoft Entra ID tenant and uses Azure Virtual Desktop (AVD). You need to ensure that AVD session hosts in a virtual network can access on-premises resources securely without exposing the session hosts to the internet. The on-premises network is connected to Azure via ExpressRoute. All AVD traffic should be routed through the ExpressRoute connection. You have already deployed a reverse connect transport for AVD. What else should you configure to meet the requirements?

Hard
140

Your company has deployed Azure Kubernetes Service (AKS) in a virtual network. The AKS cluster needs to pull images from a private Azure Container Registry (ACR) that has a private endpoint configured. The virtual network where AKS is deployed is peered to the ACR's virtual network. You have configured the AKS cluster to use managed identity for authentication to ACR. However, the AKS cluster is unable to pull images from the ACR. You need to resolve the connectivity issue without exposing the ACR to the internet. What should you do?

Medium
141

A security team needs to analyze network traffic to and from Azure virtual machines to investigate a potential security incident. They want to capture information such as source IP, destination IP, port, and protocol. Which Azure service should they enable on the network security groups (NSGs) associated with the virtual machine subnets?

Easy
142

You are a security engineer at Contoso. The company has an Azure virtual network named VNet1 with a subnet named WebSubnet that hosts internet-facing Linux VMs. You need to restrict inbound traffic to WebSubnet so that only HTTP (TCP 80) and HTTPS (TCP 443) from the internet are allowed, and all other inbound traffic is denied. The VMs must remain reachable over SSH from a jump host in another subnet for management. What should you configure?

Medium
143

You are a security engineer for a company that uses Azure Virtual Networks and Azure Private Endpoints. You have a storage account with a private endpoint in VNet1. You need to ensure that all DNS queries for the storage account's private endpoint resolve to the private IP address from any virtual machine in VNet1. The virtual machines use the default Azure-provided DNS servers. What should you do?

Medium
144

Traffic from a spoke VNet must reach the internet through a firewall in the hub VNet. What routing configuration is required on the spoke subnets?

Medium
145

You are a security engineer at Fabrikam Inc. The company has an Azure subscription with a single virtual network (VNet1) that contains a production workload. The network is connected to an on-premises data center via a site-to-site VPN. The security team requires that all Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to virtual machines in VNet1 must be brokered through Azure Bastion. Additionally, the team wants to ensure that no public IP addresses are assigned to any virtual machines in the production environment. Currently, there are several VMs with public IPs. You need to implement the requirements with minimal downtime. The solution must also ensure that administrators can access the VMs using Azure Bastion without any additional client software. What should you do?

Medium
146

A company has several Azure virtual machines (VMs) in a VNet that host a legacy application. IT support staff need to perform remote administration using RDP. The security team wants to avoid exposing the VMs to the public internet and also enforce Azure Multi-Factor Authentication (MFA) for all RDP sessions. Which Azure service should they deploy to meet these requirements?

Medium
147

You are designing a hub-spoke network topology in Azure. You need to ensure that all traffic between spokes is inspected by a network virtual appliance (NVA) deployed in the hub. What should you configure?

Easy
148

Your company uses Azure Virtual WAN with a secured virtual hub (Azure Firewall). You have branch offices connected via ExpressRoute. You need to ensure that traffic from a branch to a VNet in the same region is inspected by the firewall. You configure the default route (0.0.0.0/0) advertisement from the hub to the branch, but the traffic is not being inspected. What is the most likely reason?

Medium
149

You are reviewing an NSG rule as shown in the exhibit. This rule is applied to a subnet containing web servers. What is the security implication of this rule?

Medium
150

A public web application should be protected from OWASP-style attacks and network-layer DDoS attacks. Which two Azure services are most relevant?

Hard
151

A company has multiple on-premises web applications that need to be securely published for remote employees. The company uses Azure AD for identity management and wants to apply Conditional Access policies, including multi-factor authentication, to these applications. The security team wants to avoid exposing the on-premises infrastructure to the internet directly. Which Azure service should they deploy to meet these requirements?

Easy

Frequently asked questions

What does the Secure networking domain cover on the AZ-500 exam?
You must configure NSGs, Azure Firewall, private endpoints, VNet peering, DDoS Protection, and Bastion to secure traffic. Get rule evaluation order right: NSG priority, Azure Firewall DNAT/network/application rules, and effective routes.
How many questions are in this domain?
This page lists all 151 Secure networking questions in the AZ-500 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Secure networking questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
az-500 AZ-500 secure networking Practice Questions