Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company is concerned about Distributed Denial of Service (DDoS) attacks targeting its public-facing Azure applications. They need a service that provides enhanced DDoS protection capabilities beyond the basic protection offered by Azure's platform, including attack analytics and telemetry. Which Azure security service should they implement?

  1. AAzure Network Security Groups (NSG)
  2. BAzure Firewall
  3. CAzure DDoS Protection Standard
  4. DAzure Private Link
Show answer & explanation

Correct answer: C. Azure DDoS Protection Standard

Azure DDoS Protection Standard provides enhanced DDoS mitigation capabilities for Azure resources, offering attack detection, auto-tuning, and telemetry, alerting, and metrics that are not included in the basic platform-level protection.

Why the other options are wrong

  • A. Azure Network Security Groups (NSGs) filter network traffic at the VM or subnet level, not providing DDoS protection at scale.
  • B. Azure Firewall is a managed, cloud-based network security service that protects Azure Virtual Network resources, but doesn't specifically provide advanced DDoS protection.
  • D. Azure Private Link provides private connectivity to Azure services, unrelated to DDoS protection.

Azure DDoS Protection Standard

An Azure service that provides enhanced protection against Distributed Denial of Service (DDoS) attacks for Azure resources.

  • Offers advanced mitigation capabilities beyond basic platform protection.
  • Includes attack analytics, telemetry, and alerting.
  • Protects resources within a Virtual Network.

Memory trick: DDoS Standard is the 'strong shield' that gives you 'insights' into 'attacks'.

More Describe Azure identity, security, and networking questions