Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Which TWO Azure services should you use to implement a defense-in-depth strategy for protecting Azure virtual machines?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network Security Groups (NSGs)

Network Security Groups (NSGs) are correct because they enforce network-layer defense-in-depth by filtering inbound and outbound traffic to and from Azure VMs using allow/deny security rules based on source/destination IP, port, and protocol, effectively segmenting and restricting access at the subnet or NIC level. Azure Backup is correct because it provides the data-recovery layer of defense-in-depth, protecting VM data against accidental deletion, corruption, or ransomware by creating recoverable recovery points stored in a Recovery Services vault. Azure Logic Apps is not a security control for VMs; it is a workflow-orchestration service for integrating apps and automating business processes. Azure Automation is a configuration-management and process-automation service (runbooks, DSC, update management) and does not itself provide a protective security boundary for VM traffic or data. Azure Front Door is a global layer-7 web application delivery and CDN/WAF service for HTTP/HTTPS workloads, not a mechanism for protecting Azure VMs directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network Security Groups (NSGs)

    Why this is correct

    Network Security Groups (NSGs) are stateful packet-filtering controls that protect Azure virtual networks by enforcing allow/deny rules on inbound and outbound traffic to subnets and NICs. They operate at layers 3 and 4, matching source/destination IPs, ports, and protocols, with a default-deny rule at the end. NSGs provide essential network segmentation and perimeter defense, forming a fundamental preventive layer in a defense-in-depth strategy against lateral movement and unauthorized access.

  • ✗

    Azure Logic Apps

    Why it's wrong here

    Azure Logic Apps is a cloud-based integration platform for orchestrating workflows, connecting APIs, and automating business processes—not a security control. It does not filter traffic, inspect packets, or protect resources from threats; it simply executes logic. While Logic Apps can be used to automate security response actions, it lacks the inherent protective functions needed for defense-in-depth, making it an incorrect choice for directly implementing security controls.

  • ✓

    Azure Backup

    Why this is correct

    Azure Backup is a data protection service that securely backs up Azure VMs, SQL databases, SAP workloads, and on-premises servers, enabling recovery after ransomware, accidental deletion, or disaster. Backup is a cornerstone of defense-in-depth because it addresses the recovery pillar rather than prevention; it ensures business continuity and mitigates the impact of a compromise. Features like soft delete and immutability further harden backups against malicious tampering, making it a critical security resilience layer.

  • ✗

    Azure Automation

    Why it's wrong here

    Azure Automation is a service for process automation, configuration management, and update management, primarily used to streamline operational tasks, not to enforce security. It can deploy security configurations or runbooks in response to alerts, but it does not intrinsically filter traffic, block attacks, or protect data. Treating Azure Automation as a security control is incorrect because it lacks the granular, stateful inspection capabilities of services like NSGs and is better classified as an orchestration tool.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global, scalable entry point for web applications, providing load balancing, SSL termination, and content delivery acceleration. While it can be integrated with Azure Web Application Firewall (WAF) to filter traffic, Front Door itself is not a security service—it is an application delivery controller. Relying on Front Door without additional security layers would leave network-level filtering and backup protection unaddressed, so it does not implement defense-in-depth as a dedicated security control.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.