exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 6 question 23 discussion

Actual exam question from Microsoft's AZ-500
Question #: 23
Topic #: 6
[All AZ-500 Questions]

You have an Azure subscription that contains the resources shown in the following table.



You create an Azure DDoS Protection plan named DDoS1 in the West US Azure region.

Which resources can you add to DDoS1?

  • A. VNetl1only
  • B. WebApp1 only
  • C. VNet1 and VNet2 only
  • D. VNet1 and WebApp1 only
  • E. VNet1, VNet2, and WebApp1
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
chiquito
Highly Voted 1 year, 1 month ago
Answer E: is correct Note Although DDoS Protection Plan resources needs to be associated with a region, users can enable DDoS protection on Virtual Networks in different regions and across multiple subscriptions under a single Microsoft Entra tenant. Reference: https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection https://learn.microsoft.com/en-us/answers/questions/951433/how-to-protect-azure-webapp-from-denial-of-service https://www.examtopics.com/exams/microsoft/az-500/view/29/#
upvoted 11 times
schpeter_091
5 months, 1 week ago
"Directly adding DDoS protection to an individual web app is not possible, but you can protect your web apps indirectly by protecting the underlying infrastructure." It means, Web app can be protected, but not directly. Only with WAF.
upvoted 2 times
...
...
ITFranz
Most Recent 3 weeks, 6 days ago
Selected Answer: C
To support the answer: No, an Azure DDoS Protection Plan (like the one named DDoS1) cannot be directly added to an Azure Web App in the West US region or any other region. This is because Azure DDoS Protection is designed to protect resources deployed within virtual networks, such as virtual machines, load balancers, or application gateways. Azure Web Apps, on the other hand, are part of the App Service platform and do not reside within a virtual network by default. Answer: C
upvoted 1 times
...
golitech
3 months ago
Selected Answer: C
C. VNet1 and VNet2 only Explanation: Azure DDoS Protection is designed to protect Virtual Networks (VNets), not individual web applications like Azure Web Apps (App Services). DDoS Protection Plans can only be linked to VNets. Web App Services (like WebApp1) are PaaS services and are not directly protected by DDoS Protection Plans. Instead, Azure Web Apps are automatically protected by Azure’s built-in global DDoS protection, but they cannot be linked to a DDoS Protection Plan. VNets in any region can be linked to a DDoS Protection Plan, even if they are in different regions than the plan itself. So, even though DDoS1 is in West US, you can still add VNet2 from East US to it. Resource Analysis: VNet1 (West US) → ✅ Can be added. VNet2 (East US) → ✅ Can be added. WebApp1 (West US) → ❌ Cannot be added (Azure Web Apps are not VNet-dependent and are not protected by DDoS Protection Plans).
upvoted 2 times
...
JBAnalyst
4 months, 2 weeks ago
Selected Answer: C
Tested in lab created a ddos plan and the only protected resources I could select are vnet, firewall, application gateway, bastion host, load balancer, NIC, VMSS, and vnet gateway. No option for a webapp directly, Only via the app gateway
upvoted 4 times
...
egore_E3
5 months, 2 weeks ago
Why wouldnt it be C then?
upvoted 2 times
...
pentium75
9 months, 1 week ago
Selected Answer: C
"A DDoS protection plan defines a set of virtual networks that have DDoS Network Protection enabled ... Although DDoS Protection Plan resources needs to be associated with a region, users can enable DDoS protection on Virtual Networks in different regions" https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection (For DDoS protection of a Web App, you need WAF, not a "DDoS Protection Plan".)
upvoted 3 times
...
Pillartech
9 months, 2 weeks ago
Selected Answer: E
Answer E: is correct
upvoted 1 times
...
Jimmy500
10 months, 1 week ago
I think here answer is C as in order to add DDOS protection to Web App we should have application gateway deployed to the vnet but here we can not talk about WAF deployed that is why I would go with C. Enable DDOS Protection Standard on the virtual network hosting your App Service's Web Application Firewall. Azure provides DDoS Basic protection on its network, which can be improved with intelligent DDoS Standard capabilities which learns about normal traffic patterns and can detect unusual behavior. DDoS Standard applies to a Virtual Network so it must be configured for the network resource in front of the app, such as Application Gateway or an NVA. https://learn.microsoft.com/en-us/security/benchmark/azure/baselines/app-service-security-baseline BR
upvoted 4 times
93b98ea
10 months ago
Agreed, "or web applications protection at layer 7, you need to add protection at the application layer using a WAF offering. For more information, see Application DDoS protection."
upvoted 1 times
...
...
RaphaelG
11 months ago
Selected Answer: E
Answer E: as per chiquito explanation
upvoted 1 times
...
e2b11ca
1 year ago
Selected Answer: C
A DDoS protection plan defines a set of virtual networks that have DDoS Network Protection enabled, across subscriptions.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago