Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

You are designing network security for a hybrid application that uses Azure Front Door and Azure Application Gateway. The application must block malicious requests at the edge before they reach the backend. You need to implement Web Application Firewall (WAF) protection with the lowest latency and the ability to inspect traffic at the application layer. Which solution should you use?

⚠ Common exam trap

Many exam-takers confuse Azure Application Gateway's WAF (which is regional and higher latency) with Azure Front Door's WAF (which is global and edge-based), leading them to choose Option B because they assume all WAF policies are equivalent, ignoring the latency and edge placement requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply WAF policy on Azure Front Door.

Azure Front Door's WAF operates at the edge of the Microsoft global network, inspecting HTTP/HTTPS traffic at the application layer (Layer 7) with minimal latency due to its distributed point-of-presence (PoP) architecture. This allows malicious requests to be blocked before they traverse the backbone to the origin, meeting the requirement for edge protection and low latency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Azure DDoS Protection on the virtual network.

    Why it's wrong here

    Enabling Azure DDoS Protection on the virtual network only mitigates volumetric (Layer 3/4) infrastructure attacks, such as SYN floods or UDP amplification, by absorbing and scrubbing traffic at the network edge. It does not inspect HTTP(S) payloads, cannot block SQL injection or cross-site scripting, and therefore offers no defense against application-layer threats that target the application itself. The question requires WAF-level inspection to filter malicious requests based on signatures and rules, which DDoS Protection fundamentally lacks.

  • ✗

    Apply WAF policy on Azure Application Gateway only.

    Why it's wrong here

    Applying a WAF policy on Azure Application Gateway only inspects traffic after it has already passed through Azure Front Door and been routed to the gateway, meaning the application is still exposed at the edge to malicious requests and the inspection adds latency as traffic traverses an extra hop. This approach fails to block attacks at the closest point to the client, allowing bad traffic to consume bandwidth and potentially reach the origin before being filtered. For a hybrid application with the need for edge protection, WAF on Front Door is the preferred placement because it inspects and discards malicious traffic before it ever reaches the gateway or internal network.

  • ✓

    Apply WAF policy on Azure Front Door.

    Why this is correct

    Applying a WAF policy on Azure Front Door is the correct choice because Front Door operates at the global edge, inspecting all incoming HTTP/S requests in the closest PoP to the client, which minimizes latency and blocks malicious traffic before it travels to the origin or Application Gateway. Front Door's WAF supports managed rule sets (e.g., OWASP Core Rule Set), custom rules, geo-filtering, rate limiting, and bot protection, allowing comprehensive application-layer defense at the edge. This design keeps the hybrid application's internal network and gateway isolated from attack traffic, reducing the risk of resource exhaustion and ensuring only legitimate requests are forwarded.

  • ✗

    Use Azure Firewall with threat intelligence-based filtering.

    Why it's wrong here

    Using Azure Firewall with threat intelligence-based filtering does not provide application-layer WAF capabilities because Azure Firewall is a stateful Layer 3/4 network firewall that filters based on IP addresses, ports, and fully qualified domain names (FQDN) via its threat intelligence feature, which blocks traffic from known malicious IPs and domains. It cannot inspect HTTP payloads for SQL injection, cross-site scripting, or other web application attacks because it lacks an application-layer web application firewall engine. While it adds a valuable perimeter security layer, it is complementary to, not a replacement for, a WAF policy on Azure Front Door or Application Gateway.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.