Courseiva
Secure networking →hardMultiple Choice

AKS Egress Restriction — Azure Firewall with FQDN Tags

You have an Azure Kubernetes Service (AKS) cluster that needs to restrict egress traffic to specific Azure services (e.g., Azure Container Registry, Azure Monitor). You want a managed solution that allows you to define FQDN-based rules. Which Azure service should you use?

⚠ Common exam trap

Many candidates confuse Network Security Groups (NSGs) as a solution for FQDN-based filtering, but NSGs only support IP-based rules and cannot resolve domain names, making Azure Firewall the only managed service that provides FQDN-based egress control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Firewall

Azure Firewall is the correct choice because it is a managed, cloud-native network security service that provides FQDN-based rules to control outbound (egress) traffic. It allows you to define application rules using fully qualified domain names (FQDNs) to restrict egress traffic to specific Azure services like Azure Container Registry and Azure Monitor, without needing to manage underlying infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Application Gateway

    Why it's wrong here

    Azure Application Gateway is an L7 load balancer that routes inbound HTTP/HTTPS traffic to back-end applications, typically as an ingress controller for AKS. It has no data-plane capability to inspect or filter traffic leaving the cluster; its URL and header routing rules apply only to client requests arriving at the gateway, not to egress traffic from pods or nodes. Thus, it cannot enforce outbound FQDN allow/deny policies.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global, multi-region load balancer and application accelerator that sits on the inbound path, routing external clients to your origins and caching content. It operates entirely in front of your public endpoints and never carries internal traffic originating from your AKS cluster toward external FQDNs. Consequently, it cannot serve as an egress control plane for outbound traffic filtering.

  • ✗

    Network Security Groups (NSGs)

    Why it's wrong here

    Network Security Groups are stateful, distributed packet filters applied at subnets or NICs. They evaluate source/destination IP addresses, ports, and protocol but are not FQDN-aware, meaning you cannot create a rule that allows only api.example.com. To limit egress to a domain, you would have to manually resolve each FQDN to IP addresses and manage their churn, which is impractical and not an FQDN-filtering capability.

  • ✓

    Azure Firewall

    Why this is correct

    Azure Firewall is a managed, cloud-native firewall service that provides application rules specifically designed for outbound FQDN filtering. It can inspect and allow/deny traffic based on fully qualified domain names, including wildcard FQDNs and FQDN tags, by examining the HTTP Host header or TLS SNI. For an AKS cluster, you can route all egress traffic through the firewall using user-defined routes or a secured virtual hub, enabling centralized, DNS-aware policy enforcement.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.