Microsoft AZ-700 Design And Implement A Web Application Firewall (WAF) Deployment Practice Test
AZ-700 skill 5.3 | 36 original questions
This AZ-700 practice set focuses on design and implement a web application firewall (waf) deployment through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.
Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.
Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF; design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7565. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, C
Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.
B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.
C: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
D: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.
E: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.
F: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.
Learning point: AZ700-53-Q565: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall. | Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7566. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
B: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
C: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
D: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.
E: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
Learning point: AZ700-53-Q566: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7567. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
B: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
C: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
D: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
E: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.
Learning point: AZ700-53-Q567: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
Alpine Ski House is reviewing a global application estate serving users on three continents. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7568. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.
B: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
D: Not selected. This directly satisfies the requirement to design a Virtual WAN architecture, including selecting types and services. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.2, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
E: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
Learning point: AZ700-53-Q568: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7569. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
B: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.
C: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
Learning point: AZ700-53-Q569: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7570. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
B: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
C: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.
D: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
E: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
Learning point: AZ700-53-Q570: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7571. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
B: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
D: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
E: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
Learning point: AZ700-53-Q571: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7572. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
C: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
D: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
E: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
Learning point: AZ700-53-Q572: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7573. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.
B: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
Learning point: AZ700-53-Q573: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
Alpine Ski House is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7574. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
B: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.
C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
D: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
Learning point: AZ700-53-Q574: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7575. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
B: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
C: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.
D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
E: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
Learning point: AZ700-53-Q575: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7576. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
B: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
D: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.
E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
Learning point: AZ700-53-Q576: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7577. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
B: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
C: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
D: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6.
E: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.
Learning point: AZ700-53-Q577: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7578. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
B: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
C: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
D: Not selected. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
E: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
Learning point: AZ700-53-Q578: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7579. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
B: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
D: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
E: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
Learning point: AZ700-53-Q579: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7580. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
B: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
C: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.
D: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
E: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
Learning point: AZ700-53-Q580: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7581. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
C: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
D: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.
E: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
Learning point: AZ700-53-Q581: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7582. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
C: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
E: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.
Learning point: AZ700-53-Q582: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7583. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.
B: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
C: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
D: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
E: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
Learning point: AZ700-53-Q583: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy; associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7584. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, B
Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.
B: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
C: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
F: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
Learning point: AZ700-53-Q584: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway. | Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7585. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
B: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
C: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
Learning point: AZ700-53-Q585: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7586. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
B: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
C: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
D: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
Learning point: AZ700-53-Q586: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7587. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
D: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.
E: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
Learning point: AZ700-53-Q587: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7588. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.2, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
B: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
C: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
D: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
E: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.
Learning point: AZ700-53-Q588: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7589. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.
B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
C: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
D: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
Learning point: AZ700-53-Q589: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
Alpine Ski House is reviewing a regulated production subscription with strict change control. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7590. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
B: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.
C: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
D: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
E: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
Learning point: AZ700-53-Q590: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy; associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7591. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, C
Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
B: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
C: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.
D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
F: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.
Learning point: AZ700-53-Q591: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway. | Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7592. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create and configure explicit outbound rules, including source network address translation (SNAT). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.11, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
B: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
C: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
E: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
Learning point: AZ700-53-Q592: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7593. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
B: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
C: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
D: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
Learning point: AZ700-53-Q593: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7594. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
B: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
C: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.2.
E: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.
Learning point: AZ700-53-Q594: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7595. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.
B: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
C: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.3.
Learning point: AZ700-53-Q595: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
Alpine Ski House is reviewing a regulated production subscription with strict change control. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7596. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
B: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.
C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
D: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.4.
Learning point: AZ700-53-Q596: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7597. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
C: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.
D: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.5.
Learning point: AZ700-53-Q597: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy; associate a WAF policy; map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7598. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: A, D, F
Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.
B: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7, 5.3.1.
C: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7, 5.3.1.
D: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
E: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7, 5.3.1.
F: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
Learning point: AZ700-53-Q598: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway. | Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced. | Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7599. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
B: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
C: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
D: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.
E: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.7.
Learning point: AZ700-53-Q599: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7600. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
B: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
C: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
D: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.
E: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.
Learning point: AZ700-53-Q600: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
Popular posts
Recent Posts
