AZ-500 Secure networking Practice Question
You are configuring Azure DDoS Network Protection for your VNet. Which TWO benefits does enabling DDoS Protection Standard provide?
⚠ Common exam trap
Many exam-takers confuse Azure DDoS Protection Standard with a full web application firewall (WAF) or assume it provides Layer 7 protection, when in fact it is strictly a network-layer (L3/L4) defense with adaptive tuning and cost protection as its key differentiators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adaptive tuning to baseline traffic patterns.
Option B is correct because Azure DDoS Protection Standard continuously monitors traffic and uses adaptive tuning to learn your application's normal traffic patterns, then automatically adjusts mitigation thresholds to match that baseline, enabling accurate detection of anomalies. Option E is correct because DDoS Protection Standard includes cost protection, which provides service credits for resource costs (such as scaled-out VM instances) incurred as a result of a documented DDoS attack. Option A is incorrect because DDoS Protection Standard does not perform packet inspection through Azure Firewall integration; it operates at Layers 3/4 within the Azure network fabric. Option C is incorrect because Layer 7 application protection is provided by Azure Web Application Firewall (WAF) on Application Gateway or Front Door, not by DDoS Protection Standard itself. Option D is incorrect because vulnerability scanning is not a DDoS Protection Standard feature; it is offered through separate services such as Microsoft Defender for Cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Integration with Azure Firewall for packet inspection.
Why it's wrong here
Azure DDoS Protection operates at the network and transport layers (L3/L4), using Azure's global edge infrastructure to absorb volumetric attacks. It does not perform packet inspection at the application layer, nor does it integrate with Azure Firewall for that purpose. Azure Firewall is a separate, stateful packet-filtering service that inspects traffic based on rules; DDoS Protection and Azure Firewall work independently, and DDoS Protection does not rely on or integrate with firewall inspection to detect or mitigate attacks.
- ✓
Adaptive tuning to baseline traffic patterns.
Why this is correct
Adaptive tuning is a core feature of Azure DDoS Protection Standard. It uses machine learning algorithms to analyze each protected resource's typical traffic patterns over time, then automatically adjusts detection thresholds to match that baseline. This reduces false positives and ensures that legitimate traffic is not blocked during normal spikes, while still flagging anomalies that indicate a DDoS attack. It requires no manual configuration, as the thresholds self-tune continuously.
- ✗
Application-layer (Layer 7) protection via integrated WAF.
Why it's wrong here
Azure DDoS Protection mitigates attacks only at Layers 3 and 4 of the OSI model (network and transport), such as SYN floods, UDP floods, and other volumetric attacks. Application-layer (Layer 7) attacks like SQL injection or cross-site scripting require a Web Application Firewall (WAF), which is a separate service (e.g., Azure Application Gateway WAF, Azure Front Door WAF). DDoS Protection does not include or integrate a WAF as part of its service; customers must deploy WAF independently for L7 protection.
- ✗
Vulnerability scanning for web applications.
Why it's wrong here
DDoS Protection is a network resilience service designed to absorb volumetric attacks, not a security assessment tool. Vulnerability scanning, which identifies software weaknesses, is provided by services like Microsoft Defender for Cloud (formerly Azure Security Center) or Azure Defender's vulnerability assessment capabilities. These scan for missing patches, misconfigurations, and other CVEs, whereas DDoS Protection focuses solely on availability during large-scale traffic floods. Associating the two is a misunderstanding of their distinct scopes.
- ✓
Cost protection for scaled resources during an attack.
Why this is correct
Azure DDoS Protection Standard includes cost protection, which shields customers from extra billing charges incurred when their Azure resources elastically scale out as a direct result of DDoS attack traffic. This applies to services like Azure App Service, Virtual Machine Scale Sets, and Load Balancer, where auto-scaling during an attack could otherwise inflate costs. It ensures customers are not financially penalized for being targeted, provided the scaling is attributable to the DDoS mitigation process.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.