Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A security architect is designing an infrastructure security strategy for a highly regulated environment that requires stringent control over network traffic. All outbound connections from Azure Virtual Machines (VMs) to the internet must be inspected, filtered, and logged. Additionally, the solution must support URL filtering, threat intelligence-based filtering, and TLS inspection. Which Azure service should be deployed to meet these requirements?

  1. AAzure Network Security Groups (NSGs)
  2. BAzure Firewall Standard
  3. CAzure Application Gateway with WAF
  4. DAzure Firewall Premium
Show answer & explanation

Correct answer: D. Azure Firewall Premium

Azure Firewall Premium is specifically designed for highly sensitive and regulated environments, offering advanced threat protection capabilities such as URL filtering, threat intelligence-based filtering, and TLS inspection for outbound traffic. This allows for deep packet inspection and granular control over all internet-bound connections from VMs.

Why the other options are wrong

  • A. NSGs provide basic L3/L4 filtering based on IP addresses and ports. They do not support URL filtering, threat intelligence, or TLS inspection.
  • B. Azure Firewall Standard offers L3/L4 filtering, FQDN filtering, and threat intelligence-based filtering, but it lacks URL filtering and TLS inspection capabilities that are required by the scenario.
  • C. Azure Application Gateway with WAF is a web application firewall primarily focused on protecting inbound web traffic (Layer 7) to web applications. It is not designed for inspecting and filtering all outbound internet traffic from VMs.

Azure Firewall Premium Capabilities

Azure Firewall Premium extends the capabilities of Azure Firewall Standard with advanced threat protection, including TLS inspection, URL filtering, and an Intrusion Detection and Prevention System (IDPS).

  • TLS inspection for encrypted traffic.
  • URL filtering for granular outbound access control.
  • IDPS for network-based threat detection.
  • Suitable for highly sensitive and regulated environments.

Memory trick: Premium Firewall Inspects Everything before it Exits.

More Design security for infrastructure questions