Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A company is hosting several critical applications in Azure Virtual Networks (VNets). They need to implement a centralized network security solution that can filter traffic between VNets, to the internet, and on-premises, using stateful inspection and threat intelligence. This solution must also support Source Network Address Translation (SNAT) and Destination Network Address Translation (DNAT). Which Azure service should they deploy?
- AAzure Front Door
- BAzure Application Gateway
- CNetwork Security Groups (NSGs)
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Firewall
Azure Firewall is a managed, cloud-based network security service that provides highly available and scalable network threat protection for your Azure Virtual Network resources. It offers stateful inspection, built-in threat intelligence, and supports SNAT/DNAT, making it suitable for centralized VNet traffic filtering.
Why the other options are wrong
- A. Azure Front Door is a global, scalable entry point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, not for internal VNet traffic filtering.
- B. Azure Application Gateway is a web traffic load balancer that includes Web Application Firewall (WAF) capabilities, primarily for HTTP/S traffic, not general VNet traffic.
- C. NSGs provide basic layer 4 traffic filtering for individual VMs or subnets, not centralized, stateful, or threat intelligence-based filtering.
Azure Firewall
Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources with stateful inspection, built-in threat intelligence, and centralized policy management.
- Stateful firewall as a service.
- Built-in high availability and scalability.
- Supports Application, Network, and FQDN Tag rules.
- Includes SNAT and DNAT capabilities.
Memory trick: Azure Firewall: The VNet's smart gatekeeper, knowing who's who.