Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

A company is hosting several critical applications in Azure Virtual Networks (VNets). They need to implement a centralized network security solution that can filter traffic between VNets, to the internet, and on-premises, using stateful inspection and threat intelligence. This solution must also support Source Network Address Translation (SNAT) and Destination Network Address Translation (DNAT). Which Azure service should they deploy?

  1. AAzure Front Door
  2. BAzure Application Gateway
  3. CNetwork Security Groups (NSGs)
  4. DAzure Firewall
Show answer & explanation

Correct answer: D. Azure Firewall

Azure Firewall is a managed, cloud-based network security service that provides highly available and scalable network threat protection for your Azure Virtual Network resources. It offers stateful inspection, built-in threat intelligence, and supports SNAT/DNAT, making it suitable for centralized VNet traffic filtering.

Why the other options are wrong

  • A. Azure Front Door is a global, scalable entry point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, not for internal VNet traffic filtering.
  • B. Azure Application Gateway is a web traffic load balancer that includes Web Application Firewall (WAF) capabilities, primarily for HTTP/S traffic, not general VNet traffic.
  • C. NSGs provide basic layer 4 traffic filtering for individual VMs or subnets, not centralized, stateful, or threat intelligence-based filtering.

Azure Firewall

Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources with stateful inspection, built-in threat intelligence, and centralized policy management.

  • Stateful firewall as a service.
  • Built-in high availability and scalability.
  • Supports Application, Network, and FQDN Tag rules.
  • Includes SNAT and DNAT capabilities.

Memory trick: Azure Firewall: The VNet's smart gatekeeper, knowing who's who.

More Implement platform protection questions