SC-100 Design security solutions for infrastructure Practice Question
A company uses Azure Front Door to publish a web application globally. They need to protect against DDoS attacks and web application attacks (SQL injection, XSS). Which two services should they enable in combination?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure DDoS Protection Standard and Azure WAF policy on Front Door
Azure DDoS Protection protects against volumetric DDoS attacks. Azure Web Application Firewall (WAF) in Front Door protects against application-layer attacks. Azure Firewall is for network-layer filtering. Network Security Groups (NSGs) are for subnet-level filtering. Azure DDoS Protection Standard is the correct tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure DDoS Protection Standard and Azure Firewall
Why it's wrong here
Azure DDoS Protection Standard shields the network edge from volumetric attacks, but Azure Firewall operates as a stateful L3/L4 filtering service. Its application-rule capabilities only perform FQDN allow/deny filtering; they do not inspect HTTP request bodies, cookies, or headers for OWASP attacks such as SQL injection or cross-site scripting. Therefore, pairing DDoS Standard with Azure Firewall leaves application-layer attack traffic able to reach the origin web app unscathed.
- ✗
Azure WAF on Application Gateway and Network Security Groups
Why it's wrong here
Placing the WAF on a regional Application Gateway behind Azure Front Door splits global versus regional protection: Front Door routes traffic across multiple edge locations, while an Application Gateway WAF sits only in a single Azure region, creating inconsistent inspection and a management sprawl. Network Security Groups are L3/L4 access-control lists that can filter IPs and ports but have no HTTP-parsing or rule-engine capabilities to stop payload-based attacks. This combination cannot provide the centralized, global application-layer protection required at the Front Door edge.
- ✗
Azure Firewall and Azure DDoS Protection Basic
Why it's wrong here
Although Azure Firewall provides stateful network and NAT filtering, it lacks any web-application-level protocol inspection—it does not parse HTTP, nor does it execute managed rule sets like the OWASP Core Rule Set. Azure DDoS Protection Basic is an always-on, default infrastructure mitigation that has no adaptive traffic profiling, no mitigation telemetry, and no cost protection for scaled volumetric attacks, unlike DDoS Protection Standard. This pairing therefore fails to deliver both robust DDoS diagnostics and any L7 inspection.
- ✓
Azure DDoS Protection Standard and Azure WAF policy on Front Door
Why this is correct
Azure DDoS Protection Standard detects and scales to absorb volumetric (L3/L4) attacks against the application, while the Azure WAF policy applied directly to Front Door inspects every request at the L7 edge—matching rules such as the Microsoft managed rule sets and the OWASP CRS to block SQLi, XSS, and bot traffic before it nears your origin. Deploying both on Front Door gives you a single global policy plane that follows the anycast edge, enabling consistent protection with no regional split. This layered control covers the full attack chain from network flood to HTTP payload, making it the correct answer.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.