Courseiva
Secure networking →hardMultiple Choice

AZ-500 Secure networking Practice Question

Exhibit

{
  "properties": {
    "format": "Json",
    "rules": [
      {
        "name": "BlockHighRiskIPs",
        "priority": 100,
        "ruleType": "MatchRule",
        "matchConditions": [
          {
            "matchVariables": [
              {
                "variableName": "RemoteAddr"
              }
            ],
            "operator": "IPMatch",
            "negationCondition": false,
            "matchValues": [
              "10.0.0.0/8",
              "172.16.0.0/12",
              "192.168.0.0/16"
            ]
          }
        ],
        "action": "Block"
      }
    ]
  }
}

Refer to the exhibit. You have an Azure Application Gateway WAF policy with the above JSON configuration. A user from IP address 10.1.2.3 reports they cannot access the web application. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates may overlook the custom rule's IP range and assume the issue is related to SQL injection or detection mode, when in fact the problem is a simple IP-based block rule targeting private addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The custom rule blocks all private IP addresses.

The custom rule in the WAF policy explicitly blocks all traffic from IP addresses in the 10.0.0.0/8 private range. Since the user's IP address (10.1.2.3) falls within this range, the rule matches and blocks the request. The WAF policy is in prevention mode, so the rule actively blocks the request rather than just logging it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The WAF policy is in prevention mode and detected a SQL injection.

    Why it's wrong here

    The response is a block that originated from the custom rule's explicit action, not from a managed SQL injection rule. A SQL injection detection would require signature evidence such as SQL keywords or tautological expressions in the payload, and the WAF logs would reference the specific managed rule ID. Since the exhibit shows a custom rule matching private IP ranges, this explanation is incorrect even if the policy is in prevention mode.

  • ✗

    The WAF policy is set to detection mode and logs the request.

    Why it's wrong here

    Detection mode is a log-only operation: it records a request that matches a rule without stopping it, so a request that is actually blocked cannot be caused by a detection-mode policy. The custom rule in the exhibit is configured with an action of "Block" for IP address ranges, and a block action is enforced regardless of the policy's managed rule mode. Therefore, saying the policy is in detection mode and merely logs the request directly contradicts the observed blocked outcome.

  • ✗

    The custom rule is disabled due to a syntax error.

    Why it's wrong here

    The custom rule shown in the exhibit is well-formed JSON with valid condition syntax, so no syntax error is present. A disabled or invalid rule would not evaluate traffic at all, meaning the request would fall through to other rules instead of being blocked by this rule. If a custom rule had a syntax error, Azure would fail validation or omit it from evaluation, not silently disable it while still producing a block. Thus, this rationale cannot explain the blocked request.

  • ✓

    The custom rule blocks all private IP addresses.

    Why this is correct

    The custom rule explicitly defines a match condition on the client's source IP and uses action "Block" to deny traffic from RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16). Because the request's source IP falls inside 10.0.0.0/8, the custom rule matches and enforces the block immediately. In Application Gateway WAF, custom rules are evaluated before managed rule sets, so this request is denied without ever being inspected for SQL injection or other managed signatures.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.