Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
{
  "properties": {
    "displayName": "Block malicious IP",
    "description": "Blocks traffic from known malicious IP addresses.",
    "securityPolicy": {
      "isEnabled": true,
      "rules": [
        {
          "name": "BlockIP",
          "priority": 100,
          "sourceAddresses": ["10.0.0.5"],
          "destinationAddresses": ["*"],
          "access": "Deny",
          "direction": "Inbound",
          "protocol": "Any"
        }
      ]
    }
  }
}

You are analyzing a firewall policy in Azure Firewall deployed via Azure Policy. What is the effect of this rule?

⚠ Common exam trap

Many exam-takers confuse the direction of traffic (inbound vs outbound) and the action (allow vs deny), leading them to select options that reverse the source/destination or misinterpret the rule's effect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denies inbound traffic from IP 10.0.0.5 to any destination.

The rule in Azure Firewall deployed via Azure Policy uses a default deny approach for inbound traffic. Since the rule explicitly denies inbound traffic from IP 10.0.0.5 to any destination, option C is correct. Azure Firewall processes rules in a priority order, and a deny rule for inbound traffic from a specific source IP overrides any allow rules that might match the same traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allows outbound traffic from any source to IP 10.0.0.5.

    Why it's wrong here

    It misstates the configured rule's access and direction. The rule has Access set to Deny and Direction set to Inbound, so it cannot allow outbound traffic. Additionally, 10.0.0.5 is the rule's Source, not its Destination; the rule blocks traffic originating from that IP coming into the firewall, not traffic going to it.

  • ✗

    Allows inbound traffic from IP 10.0.0.5 to any destination.

    Why it's wrong here

    This option correctly identifies the inbound direction and the source IP, but it incorrectly specifies the action as Allow. The actual rule is configured with Access = Deny, meaning traffic from 10.0.0.5 to any internal destination will be blocked, not permitted. Allowing this traffic would create a security vulnerability, as the rule's explicit intent is to deny access from that source.

  • ✓

    Denies inbound traffic from IP 10.0.0.5 to any destination.

    Why this is correct

    It exactly matches the rule's configuration: Access is Deny, Direction is Inbound, Source is 10.0.0.5, and Destination is Any. When the Azure Firewall processes inbound packets, any traffic with a source IP of 10.0.0.5 will be dropped before reaching any internal resource. The 'Any' destination ensures the denial applies to all internal IP addresses, ports, and protocols, making this the accurate interpretation of the rule's intent.

  • ✗

    Denies outbound traffic from any source to IP 10.0.0.5.

    Why it's wrong here

    This option has the correct action (Deny) but incorrectly reverses the direction and the source/destination mapping. The rule is inbound, not outbound, so it applies to traffic arriving at the firewall from outside, not leaving the network to 10.0.0.5. As configured, the source IP is 10.0.0.5, whereas this option treats 10.0.0.5 as the destination, which would reflect a completely different rule and misrepresent the security posture.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.