AZ-500 Secure networking Practice Question
You are designing a secure network for an e-commerce application in Azure. The application consists of web servers, application servers, and database servers. You need to ensure that inbound traffic is filtered at multiple layers. Which THREE Azure services should you use to implement defense in depth for network security?
⚠ Common exam trap
Test-takers frequently confuse Azure Bastion as a network security filtering service because it secures management access, but it does not filter inbound application traffic and is not part of a defense in depth strategy for application-layer protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway with WAF policy
Azure Application Gateway with WAF policy (A) is correct because it provides layer 7 (HTTP/HTTPS) filtering at the regional level, inspecting inbound web traffic for OWASP Top 10 threats such as SQL injection and cross-site scripting before it reaches the web servers. Azure Front Door with WAF policy (B) is correct because it adds a global layer 7 entry point with anycast routing, TLS termination, and WAF inspection at the network edge, filtering malicious inbound traffic before it enters the Azure region. Network Security Groups (C) are correct because they enforce layer 3/layer 4 stateful packet filtering on subnets and NICs, allowing you to segment web, application, and database tiers with rules based on source/destination IP, port, and protocol. Azure Bastion (D) is not correct here because it provides secure RDP/SSH access to VMs over TLS from the Azure portal and does not filter inbound application traffic. Azure DNS (E) is not correct because it is a name resolution service for hosting and resolving DNS zones, not a traffic-filtering or security control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Application Gateway with WAF policy
Why this is correct
Azure Application Gateway with WAF policy operates at Layer 7, terminating TLS and inspecting incoming HTTP/HTTPS traffic before it reaches web servers. Its managed OWASP Core Rule Set blocks common attacks such as SQL injection, XSS, and command injection, and it can also enforce URL-path-based routing and listen-level rules. Unlike network-layer controls, it decodes application payloads and can make allow/deny decisions based on request content, making it the most direct web-application protection service within a regional VNet.
- ✓
Azure Front Door with WAF policy
Why this is correct
Azure Front Door with WAF policy applies the same OWASP-based filtering at Microsoft's global edge, inspecting requests before they traverse the backbone to origin. This protects a distributed or multi-origin e-commerce deployment, with features such as geo-filtering, rate limiting, bot protection, and per-domain/custom rules. Because it operates globally via anycast, it can absorb and filter attacks closer to the client, complementing rather than replacing a regional Application Gateway.
- ✓
Network Security Groups (NSGs)
Why this is correct
Network Security Groups act at Layers 3/4 by filtering traffic flows based on source/destination IP, port, and protocol, controlled via NSG rules attached to subnets or VM NICs. They are ideal for enforcing isolation between the front-end tier, application tier, and data tier inside a virtual network. However, they cannot inspect payload contents or understand HTTP semantics, so they cannot mitigate application-layer attacks that WAF addresses.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion is a managed Platform-as-a-Service that provides secure, browser-based RDP/SSH connectivity to Azure VMs through the Azure portal over TLS. It eliminates the need to expose VMs to the internet with public IPs, but it is not an inline security appliance and does not inspect, route, or filter inbound web traffic. Its security value is in remote administration access, not application traffic protection.
- ✗
Azure DNS
Why it's wrong here
Azure DNS is a hosting service for DNS domains and records, resolving names to IPs for applications; it has no traffic inspection or access-control capabilities. While DNS can be used to steer traffic (e.g., alias records) or support private zones, it does not evaluate HTTP requests or block malicious payloads. Relying on DNS for application-layer protection would be a category error because it does not see the application payload.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.