Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard
A security architect is designing the network security for a multi-tier application deployed across several Azure Virtual Networks (VNets). The application includes web servers, application servers, and database servers, each in its own subnet. Communication between these tiers must be restricted to only the necessary ports and protocols. Additionally, communication from the application servers to external APIs must be filtered. Which Azure networking security component is most suitable for enforcing granular, stateful packet filtering between subnets and for outbound internet traffic from the application servers?
- ANetwork Security Groups (NSGs)
- BAzure Application Gateway
- CAzure Front Door
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Firewall
Azure Firewall provides stateful, centralized network firewall as a service, offering high-level filtering capabilities for both VNet-to-VNet and outbound internet traffic, which is ideal for complex multi-tier applications requiring granular control and filtering to external APIs.
Why the other options are wrong
- A. Network Security Groups (NSGs) provide basic, stateless 5-tuple filtering at the NIC or subnet level. While useful, they lack the centralized management, advanced threat intelligence, and application-level filtering needed for granular outbound control to external APIs.
- B. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. It includes a Web Application Firewall (WAF) for HTTP/S traffic, but it's not designed for general network-level filtering between subnets or for outbound non-HTTP/S traffic.
- C. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It's a CDN and WAF, not a VNet firewall.
Azure Firewall for VNet Segmentation
Azure Firewall is a managed, cloud-based network security service that provides centralized, stateful firewall capabilities to protect Azure Virtual Network resources, offering granular control over inbound and outbound network traffic.
- Stateful firewall as a service.
- Supports VNet-to-VNet and VNet-to-Internet filtering.
- Provides FQDN filtering for outbound traffic.
- Offers centralized management and logging.
Memory trick: Firewall Filters All VNet Traffic Deeply.