Exam SC-100 Topic 2 Question 249 Discussion

Actual exam question for Microsoft's SC-100 exam
Question #: 249
Topic #: 2
Hotspot Question
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a
10-node virtual machine scale set that hosts a web search app named App1. Customers access App1 from the internet. The nodes establish outbound HTTP and HTTPS connections to the internet.
You need to recommend a network security solution for App1. The solution must meet the following requirements:
- Inbound connections to App1 that contain security threats specified
in the Core Rule Set (CRS) from the Open Web Application Security
Project (OWASP) must be blocked.
- Outbound HTTP and HTTPS connections from the virtual machine scale
set that contain security threats identified by the Microsoft Defender
Threat Intelligence (Defender TI) feed must be blocked.
What should you include in the recommendation? To answer, select the options in the answer area.
NOTE: Each correct answer is worth one point.

Suggested Answer:


Explanation:
Box 1: Azure Web Application Firewall (WAF)
Inbound connections to App1 that contain security threats specified in the Core Rule Set (CRS) from the Open Web Application Security Project (OWASP) must be blocked.
The Azure Web Application Firewall (WAF) on Azure Application Gateway actively safeguards your web applications against common exploits and vulnerabilities. As web applications become more frequent targets for malicious attacks, these attacks often exploit well-known vulnerabilities such as SQL injection and cross-site scripting.
WAF on Application Gateway is based on the Core Rule Set (CRS) from the Open Web Application Security Project (OWASP).
Box 2: Azure Firewall
Outbound HTTP and HTTPS connections from the virtual machine scale set that contain security threats identified by the Microsoft Defender Threat Intelligence (Defender TI) feed must be blocked.
Azure Firewall threat intelligence-based filtering
You can enable Threat intelligence-based filtering for your firewall to alert and deny traffic from/to known malicious IP addresses, FQDNs, and URLs. The IP addresses, domains and URLs are sourced from the Microsoft Threat Intelligence feed, which includes multiple sources including the Microsoft Cyber Security team. Intelligent Security Graph powers Microsoft threat intelligence and uses multiple services including Microsoft Defender for Cloud.
Reference:
https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview
https://learn.microsoft.com/en-us/azure/firewall/threat-intel

by Hiram at Aug 16, 2026, 12:54 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10