Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global enterprise is designing its multi-region Azure architecture to host critical web applications. The security team requires a highly scalable, cloud-native firewall solution that can provide advanced threat protection capabilities, including TLS/SSL inspection, URL filtering, and IDPS (Intrusion Detection and Prevention System), for outbound traffic from Azure Virtual Networks. Which Azure service should the architect recommend?

  1. ANetwork Security Groups (NSGs)
  2. BAzure Firewall Standard
  3. CAzure Firewall Premium
  4. DAzure Application Gateway with WAF
Show answer & explanation

Correct answer: C. Azure Firewall Premium

Azure Firewall Premium is the only Azure native firewall service that offers advanced threat protection capabilities such as TLS/SSL inspection, URL filtering, and IDPS for both inbound and outbound traffic. This makes it suitable for securing critical enterprise applications with stringent security requirements.

Why the other options are wrong

  • A. Network Security Groups (NSGs) provide basic stateful packet filtering at the network interface or subnet level and do not offer advanced features like TLS/SSL inspection, URL filtering, or IDPS.
  • B. Azure Firewall Standard provides basic stateful firewall capabilities, FQDN filtering, and threat intelligence, but it lacks advanced features like TLS/SSL inspection, URL filtering on HTTPS, and IDPS, which are required.
  • D. Azure Application Gateway with WAF (Web Application Firewall) is an application delivery controller and WAF that protects web applications from common web exploits. It operates at Layer 7 (HTTP/S) for inbound traffic to web applications but does not provide general outbound network protection with IDPS or comprehensive URL filtering for all traffic types.

Azure Firewall Premium

A cloud-native, highly scalable network security service that provides advanced threat protection capabilities, including TLS/SSL inspection, URL filtering, and IDPS, for all traffic flows across Azure Virtual Networks.

  • Cloud-native, highly scalable firewall
  • Provides advanced threat protection (IDPS, TLS/SSL inspection, URL filtering)
  • Centralized management and logging
  • Supports both inbound and outbound traffic filtering

Memory trick: Premium Firewall: Inspect, Filter, Detect, Block.

More Design security for applications and data questions