Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is designing a secure network infrastructure for a multi-cloud environment that includes Azure, AWS, and on-premises datacenters. The security team requires that all traffic between these environments be inspected for threats and that any malicious traffic be automatically blocked. The solution must minimize complexity and use a single pane of glass for policy management. Which Azure service should you use as the central hub?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Firewall

Azure Firewall (option D) is the correct choice because it provides a centralized, cloud-native firewall service that can inspect and filter traffic across Azure, AWS, and on-premises connections through a hub-and-spoke or Virtual WAN topology, with a single management plane via Azure Firewall Manager for policy and threat intelligence-based blocking. It supports FQDN filtering, threat intelligence, and IDPS, making it suitable for multi-cloud traffic inspection and automatic malicious traffic blocking while minimizing complexity. Azure Front Door (A) is a global HTTP/HTTPS load balancer and WAF for web applications, not a general network traffic inspection hub for multi-cloud and on-premises traffic. Network Security Groups (B) are stateful packet filters at the subnet/NIC level with no central management pane or advanced threat inspection. Azure DDoS Protection (C) only mitigates volumetric DDoS attacks against Azure resources and does not inspect or block general malicious traffic across hybrid and multi-cloud environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a Layer 7 reverse proxy, CDN, and global load balancer that accelerates and protects HTTP/S web applications, with optional WAF and TLS termination. It only inspects and routes application-level traffic, not the raw TCP/UDP packets between virtual networks or environments. Therefore, it cannot enforce IP/port-based network policies for inter-environment traffic, making it unsuitable as a network firewall.

  • ✗

    Network Security Groups (NSGs)

    Why it's wrong here

    Network Security Groups (NSGs) provide distributed, stateful filtering at the subnet or NIC level based on source/destination IP, port, and protocol. However, they lack centralized policy management, real-time threat intelligence, FQDN-based outbound rules, and deep packet inspection capabilities, and they cannot be applied consistently across hybrid or multi-cloud environments. NSGs are best used as a defense-in-depth layer rather than the primary inter-environment traffic inspection control.

  • ✗

    Azure DDoS Protection

    Why it's wrong here

    Azure DDoS Protection is a dedicated service that mitigates large-scale volumetric, protocol, and resource-layer DDoS attacks using Azure's global network capacity. It does not inspect or control legitimate traffic flows between environments, nor does it enforce allow/deny policies based on application, user, or security rules. It is complementary to a firewall but absolutely cannot replace the centralized network traffic inspection required for inter-environment security.

  • ✓

    Azure Firewall

    Why this is correct

    Azure Firewall is a fully stateful, centrally managed firewall-as-a-service that provides both network and application-level filtering (including FQDN rules and threat intelligence) for Azure virtual networks and hybrid connections over ExpressRoute or VPN. Deployed in a hub virtual network, it can inspect all inter-environment traffic via user-defined routes and forced tunneling, with native integration into Azure Monitor for centralized logging and alerting. This combination of centralized policy management, advanced inspection, and hybrid/multi-cloud applicability makes it the correct choice for a secure network infrastructure.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.