ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 43 - AZ-720 discussion

Report
Export

A company has an Azure tenant. The company deploys an Azure Firewall named FW1 using the Standard SKU. You configure FW1 using classic firewall rules. The company creates an application rule collection with the following settings:

Priority: 100

Action: Deny

Rule type: FQDN

Source type: IP address

Source: *

Protocol: http:80,https:443

Target FQDN: *.cloud.contoso.com

An engineer observes that traffic to console.cloud.conotoso.com is still allowed by FW1.

You need to determine why the traffic is allowed.

What should you review?

A.
Network rules
Answers
A.
Network rules
B.
Web categories
Answers
B.
Web categories
C.
Infrastructure rules
Answers
C.
Infrastructure rules
D.
Application rules
Answers
D.
Application rules
Suggested answer: A

Explanation:

To determine why the traffic is allowed, you should review network rules. According to 3, Azure Firewall uses network rules to allow or deny traffic based on source and destination IP address, port, and protocol. Network rules are applied before application rules and have higher priority than application rules. Therefore, if there is a network rule that allows traffic to console.cloud.contoso.com on port 80 or 443, it will override the application rule that denies traffic based on FQDN.

asked 02/10/2024
Alemu, Fissha
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first