Courseiva

AZ-500 · topic practice

Secure networking practice questions

Secure networking is 24% of AZ-500 and covers designing and configuring network controls that protect Azure workloads. Expect scenario items on NSG and Azure Firewall rules, service endpoints versus private endpoints, VNet peering and routing, DDoS Protection, and Bastion or VPN access, plus interpreting effective security rules and diagnosing connectivity failures.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Secure networking

What the exam tests

What to know about Secure networking

You must configure NSGs, Azure Firewall, private endpoints, VNet peering, DDoS Protection, and Bastion to secure traffic. Get rule evaluation order right: NSG priority, Azure Firewall DNAT/network/application rules, and effective routes.

Configuring NSG security rules, priorities, and application security groups for subnet traffic

Choosing Azure Firewall, NSG, or WAF for filtering and inspecting network flows

Implementing Private Link and private endpoints versus service endpoints for PaaS access

Securing remote administration with Azure Bastion, VPN Gateway, and Just-in-Time VM access

Watch out for

Common Secure networking exam traps

  • ▸Assuming service endpoints provide private IP connectivity; they only restrict access over the Azure backbone while traffic still uses public endpoints.
  • ▸Forgetting that NSG rules are stateful and that a lower-priority number wins, so deny rules can silently override intended allow rules.
  • ▸Believing Azure Firewall replaces NSGs; both are needed since NSGs filter at subnet/NIC level and Firewall handles centralized egress and FQDN filtering.

Practice set

Secure networking questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Review the full subnetting walkthrough →

A company has a hub-spoke network topology. The hub virtual network contains an Azure Firewall and an ExpressRoute gateway for on-premises connectivity. The spoke virtual network hosts a critical application. They need to ensure that all outbound traffic from the spoke to the internet and to on-premises networks is routed through the Azure Firewall. They configure a user-defined route (UDR) on the spoke subnet with address prefix 0.0.0.0/0 and next hop as the Azure Firewall's private IP. They also disable 'Virtual network gateway route propagation' on the spoke subnet. However, traffic to on-premises still bypasses the firewall and goes through the ExpressRoute gateway. What is the most likely cause?

Question 2hardmultiple choice
Review the full subnetting walkthrough →

A company has an Azure virtual network that uses Azure Firewall as the central traffic inspection point. They have a spoke VNet peered to the hub VNet. The spoke VNet contains a subnet with virtual machines. The security team wants to ensure that all outbound traffic from those virtual machines to the internet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) to the Azure Firewall's private IP. However, traffic from the VMs is still going directly to the internet. What is the most likely cause?

Question 3hardmultiple choice
Review the full subnetting walkthrough →

A company has two Azure virtual networks: VNet-A and VNet-B. They peer the VNets and deploy a network virtual appliance (NVA) in VNet-A. They want to inspect all outbound traffic from VNet-B to the internet using the NVA. They configure a user-defined route (UDR) in a route table associated with the subnet in VNet-B, with a default route (0.0.0.0/0) and next hop set to the private IP of the NVA in VNet-A. However, outbound traffic from VNet-B still goes directly to the internet. What is the most likely cause?

Question 4hardmultiple choice
Review the full subnetting walkthrough →

A company has two Azure virtual networks, VNet-A (hub) and VNet-B (spoke), connected via VNet peering. They deploy a network virtual appliance (NVA) in a subnet in VNet-A to inspect all traffic between the VNets. They configure a user-defined route (UDR) on the subnet in VNet-B with the destination address space of VNet-A (10.0.0.0/16) and the next hop set to the private IP of the NVA. However, traffic from VNet-B to VNet-A still bypasses the NVA and takes a direct path. What is the most likely cause?

Question 5mediummultiple choice
Review the full subnetting walkthrough →

A company has an Azure virtual network with a subnet that hosts Azure virtual machines. They want to restrict access to an Azure SQL Database so that only traffic originating from that specific subnet is allowed. They have enabled a service endpoint for Microsoft.Sql on the subnet and configured the SQL server firewall to allow only that subnet's virtual network rule. However, connections from the VMs to the SQL database are failing with an authorization error. What is the most likely cause?

Question 6hardmultiple choice
Review the full subnetting walkthrough →

A company has two Azure virtual networks, VNet-A (hub) and VNet-B (spoke), connected via VNet peering. They deployed a network virtual appliance (NVA) in a subnet in VNet-A to inspect all traffic. They configured a user-defined route (UDR) on the subnet in VNet-B that points the VNet-A address space (10.0.0.0/16) to the private IP of the NVA. However, traffic initiated from VNet-B to VNet-A still takes a direct path and bypasses the NVA. What is the most likely cause?

Question 7hardmultiple choice
Review the full subnetting walkthrough →

A company has an Azure virtual network (VNet) with multiple subnets. They deploy Azure Firewall in a hub VNet and peer spoke VNets. They want to force-tunnel all outbound traffic from a specific spoke subnet to the firewall for inspection. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP as the next hop. However, traffic is still bypassing the firewall. What is the most likely cause?

Question 8mediummultiple choice
Review the full subnetting walkthrough →

Your company has two Azure virtual networks: VNet-A (10.0.0.0/16) and VNet-B (10.1.0.0/16). They are connected via VNet peering. You deploy a network virtual appliance (NVA) in a subnet in VNet-A to inspect all traffic between the VNets. You configure a user-defined route (UDR) on the subnet in VNet-B that points the address space of VNet-A (10.0.0.0/16) to the next hop as the private IP of the NVA. However, traffic from VNet-B to VNet-A still bypasses the NVA and takes the direct peered path. What is the most likely cause?

Question 9hardmultiple choice
Read the full VPN explanation →

A company has two Azure virtual networks (VNet-A and VNet-B) connected via VNet peering. They need to ensure that all traffic between the two VNets is encrypted using IPsec and that no traffic can bypass the encryption. The security team has enabled the 'Use remote virtual network gateways' setting on the peering. However, traffic is still flowing unencrypted. What additional configuration is required to enforce encryption for all traffic between the VNets?

Question 10mediummultiple choice
Review the full subnetting walkthrough →

A company has an Azure virtual network with a subnet hosting internal web applications. The security team needs to allow inbound HTTPS traffic only from the company's corporate network IP range (203.0.113.0/24). All other inbound traffic must be denied. They want to use a network security group (NSG) associated with the subnet. Which inbound security rule configuration meets this requirement?

Question 11mediummultiple choice
Read the full Secure networking explanation →

A company runs a public-facing web application on Azure App Service in the West US region. They want to protect against network-layer (Layer 3/4) DDoS attacks. The application consists of a single App Service instance. Which Azure DDoS Protection tier should they enable to meet this requirement while minimizing cost?

Question 12mediummultiple choice
Read the full VPN explanation →

A company is setting up a site-to-site VPN between an on-premises network and an Azure virtual network using an Azure VPN gateway. The security policy mandates that the VPN tunnel must use the strongest available encryption and authentication. Which IPsec/IKE parameter combination should they configure on both sides?

Question 13mediummultiple choice
Review the full subnetting walkthrough →

A virtual network has a Frontend subnet (web servers) and a Backend subnet (Azure SQL Database). The security team requires that no internet traffic can reach the Backend subnet directly, but the Frontend subnet must be able to communicate with the Backend subnet on port 1433. Which solution should they implement?

A company has multiple Azure virtual networks connected via VNet peering. They want to ensure that all traffic between the peered VNets is encrypted and that no traffic can bypass the encryption. Which configuration is required?

A web app uses Azure App Service and must access Azure SQL over a private IP without exposing SQL to the public internet. Which two components are required?

An Azure SQL Database must be accessed privately from workloads in a VNet and should not allow public network access. Which two configurations are required?

A hub-and-spoke Azure network uses Azure Firewall for egress inspection. Which two settings are typically required on spoke workloads?

You are planning a network security strategy for a multi-tier application deployed on Azure virtual machines. You need to ensure that traffic between the web tier and the application tier is encrypted and that the application tier is not directly accessible from the internet. Which three of the following should you implement? (Choose three.)

Your company has deployed an Azure Firewall in a hub virtual network to inspect traffic from spoke virtual networks. You need to ensure that all outbound traffic from a spoke virtual network to the internet is forced through the Azure Firewall. Which three of the following actions are required? (Choose three.)

You are designing a secure hybrid network that connects an on-premises datacenter to Azure. The solution must provide high availability and encrypt all traffic between the two sites. Which three of the following should you consider? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Secure networking sessions

Start a Secure networking only practice session

Every question in these sessions is drawn from the Secure networking domain — nothing else.

Related practice questions

Related AZ-500 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-500 exam test about Secure networking?
You must configure NSGs, Azure Firewall, private endpoints, VNet peering, DDoS Protection, and Bastion to secure traffic. Get rule evaluation order right: NSG priority, Azure Firewall DNAT/network/application rules, and effective routes.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Secure networking questions in a focused session?
Yes — the session launcher on this page draws every question from the Secure networking domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-500 topics?
Use the topic links above to move to related areas, or go back to the AZ-500 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-500 exam covers. They are not copied from any real exam or dump site.