Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard
A global company uses Azure Front Door to route traffic to its web applications deployed in multiple Azure regions. The security team needs to ensure that only traffic originating from specific countries is allowed to reach the application, while traffic from all other countries is blocked at the edge. Which Azure Front Door security feature should be configured to achieve this geographical filtering?
- ACustom Domains with HTTPS
- BWeb Application Firewall (WAF) with Geo-filtering
- CPrivate Link Service
- DManaged Identity Integration
Show answer & explanationAnswer & explanation
Correct answer: B. Web Application Firewall (WAF) with Geo-filtering
Azure Front Door's Web Application Firewall (WAF) can be configured with custom rules, including geo-filtering. This allows you to control access to your web applications based on the geographical location (country/region) of the client's IP address, blocking traffic from disallowed countries at the edge.
Why the other options are wrong
- A. Custom Domains with HTTPS ensures secure communication via SSL/TLS but does not provide geographical access control.
- C. Private Link Service enables private connectivity to Azure services, not geographical filtering of public internet traffic.
- D. Managed Identity Integration provides secure authentication for services, unrelated to geographical traffic filtering.
Azure Front Door WAF Geo-filtering
A feature of Azure Front Door's Web Application Firewall (WAF) that allows you to control access to your web applications based on the geographical location of the client's IP address.
- Filters traffic at the Azure edge network.
- Can block or allow traffic based on country/region.
- Part of Front Door's WAF custom rules.
Memory trick: Front Door's WAF acts as a global border patrol for your web apps.