Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium

A security auditor has identified that an Azure Virtual Network (VNet) named 'VNetHR' contains highly sensitive data. The auditor recommends restricting outbound Internet access from 'VNetHR' to only specific fully qualified domain names (FQDNs) for security updates and antivirus definitions, while blocking all other outbound Internet traffic. All internal VNet communication should remain unrestricted. Which Azure networking service should be implemented to enforce this granular outbound FQDN-based filtering?

  1. ANetwork Security Groups (NSGs)
  2. BUser-Defined Routes (UDRs)
  3. CAzure DDoS Protection
  4. DAzure Firewall
Show answer & explanation

Correct answer: D. Azure Firewall

Azure Firewall is a managed, cloud-based network security service that provides threat protection for your Azure Virtual Network resources. It offers FQDN filtering for outbound HTTP/HTTPS traffic, allowing granular control over which external domains can be accessed, which NSGs cannot do.

Why the other options are wrong

  • A. NSGs operate at Layer 4 (IP address, port, protocol) and cannot filter based on FQDNs.
  • B. UDRs control routing paths for traffic, not granular filtering based on FQDNs.
  • C. Azure DDoS Protection protects against distributed denial-of-service attacks, not outbound FQDN filtering.

Azure Firewall FQDN Filtering

Azure Firewall can filter outbound traffic based on Fully Qualified Domain Names (FQDNs), providing granular control over external access.

  • Operates at Layer 3/4 and Layer 7.
  • Supports FQDN filtering for HTTP/HTTPS and non-HTTP/HTTPS protocols.
  • Provides centralized network security across VNets and subscriptions.

Memory trick: Firewall for FQDN, NSG for IP/Port, UDR for routes.

More Implement and manage virtual networking questions