Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard
A security administrator needs to implement a system that automatically blocks network traffic from IP addresses that are known to be malicious. This system should continuously update its threat intelligence to protect Azure Virtual Networks from emerging threats. Which Azure security feature provides this capability?
- AAzure Firewall Threat Intelligence
- BAzure DDoS Protection Standard
- CNetwork Security Groups (NSG)
- DAzure Security Center (Defender for Cloud)
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Firewall Threat Intelligence
Azure Firewall includes Threat Intelligence-based filtering, which can be enabled to alert on or deny traffic to/from known malicious IP addresses and domains. This intelligence is sourced from Microsoft's threat intelligence feeds, which are continuously updated.
Why the other options are wrong
- B. Azure DDoS Protection Standard protects against distributed denial of service attacks.
- C. Network Security Groups (NSGs) use static rules defined by the user, not dynamically updated threat intelligence.
- D. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection, but not direct automated blocking of known malicious IPs at the network perimeter like Azure Firewall.
Azure Firewall Threat Intelligence
Azure Firewall's Threat Intelligence feature allows you to enable filtering to alert on or deny traffic to/from known malicious IP addresses and domains.
- Integrated with Azure Firewall
- Uses Microsoft's threat intelligence feeds
- Automatically updated for emerging threats
- Can be configured for alert or deny mode
Memory trick: Azure Firewall's Threat Intel is your smart bouncer, always checking its 'naughty list' of bad IPs.