AZ-500 Secure networking Practice Question
You are a security engineer at Litware. The company has an Azure virtual network named VNet1 with a subnet named Subnet1 that hosts several virtual machines. You need to restrict outbound internet access from Subnet1 to only allow traffic to specific FQDNs, such as *.microsoft.com and *.azure.com, while blocking all other outbound internet traffic. You also need to log allowed and denied traffic. Which two actions should you perform? (Choose two.)
⚠ Common exam trap
The trap here is assuming that network security groups can filter by FQDN or that simply deploying Azure Firewall without a user-defined route will automatically redirect traffic through it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a user-defined route (UDR) in Subnet1 that directs all outbound traffic (0.0.0.0/0) to the Azure Firewall's private IP address as the next hop.
To restrict outbound internet access to specific FQDNs and log traffic, you need Azure Firewall with application rules that allow the desired FQDNs and deny everything else. You also need a user-defined route in Subnet1 that sends all outbound traffic (0.0.0.0/0) to the firewall's private IP. This combination ensures traffic is forced through the firewall and filtered by FQDN, with logging of allowed and denied flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a user-defined route (UDR) in Subnet1 that directs all outbound traffic (0.0.0.0/0) to the Azure Firewall's private IP address as the next hop.
Why this is correct
A user-defined route with address prefix 0.0.0.0/0 and next hop type Virtual appliance, pointing to the Azure Firewall's private IP, forces all outbound traffic from Subnet1 through the firewall. Without this route, traffic would bypass the firewall and go directly to the internet, so it is essential to enforce inspection.
- ✗
Enable Azure DDoS Protection Standard on VNet1 to filter outbound traffic based on domain names.
Why it's wrong here
Azure DDoS Protection Standard is designed to protect against volumetric and protocol attacks on public endpoints. It does not filter outbound traffic or support domain name-based rules. It is not relevant to restricting outbound access to specific FQDNs.
- ✗
Configure a network security group (NSG) on Subnet1 with outbound rules that allow traffic to the FQDNs and deny all other outbound traffic.
Why it's wrong here
Network security groups cannot filter by FQDN; they only support IP addresses, CIDR ranges, service tags, and application security groups. Since the requirement is to allow specific FQDNs, NSGs alone cannot fulfill it. They also do not provide application-layer logging of FQDN-based rules.
- ✗
Deploy an Azure Application Gateway with WAF and configure custom rules to allow the FQDNs for outbound traffic.
Why it's wrong here
Application Gateway with WAF is an inbound layer 7 load balancer and web application firewall. It inspects inbound HTTP/HTTPS traffic to protect web apps, not outbound traffic from virtual machines. It cannot enforce outbound FQDN restrictions, so it does not meet the scenario's requirements.
- ✓
Deploy Azure Firewall and configure application rules to allow the specified FQDNs, then set a default deny for all other outbound traffic.
Why this is correct
Azure Firewall supports application rules based on FQDNs, allowing you to permit specific domains like *.microsoft.com and *.azure.com. By setting a default deny for other outbound traffic, you enforce the restriction. Azure Firewall also provides logging of allowed and denied traffic, satisfying the logging requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.