ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 114 - AZ-720 discussion

Report
Export

A company has a virtual machine (VM) named VM1 in a virtual network. The company also uses Azure Firewall Standard.

An administrator creates application rules to filter outbound traffic from VM1 and configure fully qualified domain names (FQDN) on the application rules.

The administrator discovers that outbound traffic from VM1 to the FQDNs are not being filtered by the firewall.

You need to resolve the issue with filtering.

What should you do first?

A.
Configure VM1 to use Azure Firewall as its DNS server.
Answers
A.
Configure VM1 to use Azure Firewall as its DNS server.
B.
Upgrade to the Azure Firewall Premium SKU.
Answers
B.
Upgrade to the Azure Firewall Premium SKU.
C.
Create a DNAT rule to route traffic to VM1.
Answers
C.
Create a DNAT rule to route traffic to VM1.
D.
Configure the firewall for a negative cache.
Answers
D.
Configure the firewall for a negative cache.
Suggested answer: A

Explanation:

Explanation: To use FQDN filtering in network rules, you must enable DNS Proxy on the firewall policy and configure the virtual machines to use the Azure Firewall as their DNS server1. This way, the firewall can resolve the FQDNs and apply the appropriate network rules based on the IP addresses returned by the DNS server2. Upgrading to the Azure Firewall Premium SKU, creating a DNAT rule, or configuring the firewall for a negative cache are not required for FQDN filtering in network rules.

1: Azure Firewall policy DNS settings 2: Azure Firewall FQDN filtering in network rules

asked 02/10/2024
Kodjo Boessi
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first