Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A company is hosting several critical applications in Azure Virtual Networks. They need to ensure that all inbound and outbound network traffic to and from these applications is inspected and filtered by a centralized, stateful firewall service. This firewall must also provide threat intelligence-based filtering and integrate seamlessly with Azure's networking ecosystem. Which Azure service is best suited for this requirement?

  1. ANetwork Security Groups (NSGs)
  2. BAzure Firewall
  3. CAzure Application Gateway
  4. DUser-Defined Routes (UDRs)
Show answer & explanation

Correct answer: B. Azure Firewall

Azure Firewall is a managed, cloud-native network security service that provides stateful firewall capabilities, built-in high availability, and threat intelligence-based filtering. It is designed to centrally protect all your Azure Virtual Network resources.

Why the other options are wrong

  • A. NSGs provide basic, stateless packet filtering at the network interface or subnet level, not advanced stateful inspection or threat intelligence.
  • C. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications, focusing on Layer 7, not a general-purpose network firewall.
  • D. UDRs are used to control the routing of network traffic within Azure Virtual Networks, not to perform stateful inspection or filtering.

Azure Firewall

A managed, cloud-native, and intelligent network firewall security service that provides threat protection for your cloud workloads running in Azure.

  • Stateful firewall as a service.
  • Built-in high availability and scalability.
  • Threat intelligence-based filtering and URL filtering.

Memory trick: Azure Firewall stands guard over your entire network.

More Implement platform protection questions