AZ-900 Describe Azure management and governance Practice Question
What is Azure DDoS Protection Standard?
⚠ Common exam trap
It's easy for candidates to confuse Azure DDoS Protection Standard with a firewall or IDS/IPS service, because all three deal with network security, but DDoS Protection Standard specifically targets availability attacks (volumetric, protocol, application-layer) rather than filtering or intrusion detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enhanced protection against distributed denial of service attacks for Azure VNet resources
Azure DDoS Protection Standard provides enhanced mitigation capabilities specifically for Azure Virtual Network (VNet) resources, defending against volumetric, protocol, and application-layer DDoS attacks. It integrates with Azure's global network to automatically detect and scrub malicious traffic, offering adaptive tuning and attack analytics. This is distinct from basic DDoS protection, which is included by default but lacks the dedicated mitigation capacity and reporting features of the Standard tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A firewall service that filters HTTP/HTTPS traffic based on rules
Why it's wrong here
Rule-based filtering of HTTP/HTTPS traffic is the responsibility of Azure Web Application Firewall (WAF), which inspects application-layer requests and blocks them based on managed rule sets such as the OWASP Core Rule Set, including protections against SQL injection and cross-site scripting. In contrast, DDoS Protection works at the network and transport layers, analyzing traffic volumes and patterns to absorb and scrub flood traffic before it reaches the application; it does not inspect HTTP headers, URLs, or request bodies. Therefore, DDoS Protection does not act as an application-layer firewall and is unable to filter based on HTTP or HTTPS rules—it only detects and mitigates large-scale attacks that attempt to overwhelm network capacity.
- ✓
Enhanced protection against distributed denial of service attacks for Azure VNet resources
Why this is correct
Azure DDoS Protection Standard (also known as DDoS Network Protection) provides enhanced, always-on, adaptive mitigation for resources in a virtual network, including VMs, load balancers, and application gateways. It continuously monitors traffic to detect volumetric, protocol, and resource-layer attacks, automatically applying mitigation policies without requiring manual intervention. The service integrates with Azure Monitor, offers real-time telemetry, and generates mitigation reports, giving security teams visibility and response capabilities. It goes beyond Azure's basic infrastructure-level DDoS protections, which only address large-scale attacks that affect the platform broadly.
- ✗
A service that encrypts data in transit between Azure regions
Why it's wrong here
Encrypting data in transit between Azure regions is accomplished through protocols such as TLS/SSL, IPsec, or HTTPS, not by DDoS Protection. For cross-region traffic, customers typically use ExpressRoute with MACsec encryption or VPN gateways that enforce IPsec tunnels to safeguard data confidentiality. DDoS Protection operates at the network and transport layers (L3/L4) to defend against packet floods like SYN floods or UDP amplification, and it does not alter, encrypt, or inspect the payloads of the traffic it is defending. Its focus is availability (keeping services online) rather than confidentiality, so it cannot satisfy any requirement for data-in-transit encryption.
- ✗
An intrusion detection system for monitoring network traffic
Why it's wrong here
Intrusion detection and prevention systems (IDS/IPS) analyze network traffic against known signatures, behavioral baselines, or anomaly scoring to identify malicious activities such as port scans, malware patterns, or lateral movement. Azure Firewall Premium offers IDPS capabilities that provide this kind of deep inspection for virtual network traffic. DDoS Protection, however, is not an intrusion detection system; its purpose is to mitigate distributed denial-of-service attacks by monitoring for anomalies indicative of a flood—such as packet amplification or unusually high volumes of TCP SYN packets—and then scrubbing the malicious traffic. It does not provide general-purpose threat detection, rather it records security alerts related to DDoS events, nor does it analyze signatures or alert on intrusion attempts outside the DDoS context.
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Azure Virtual Network
Azure Virtual Network is a cloud service that lets you create a private, isolated network in the Microsoft Azure cloud, allowing your virtual machines and other resources to communicate securely with each other, the internet, and your on-premises network.
Key term
Virtual network
A virtual network is a software-based network that connects computers, servers, and devices over the internet or within a cloud environment, simulating a physical network without requiring dedicated hardware.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.