Answer E: is correct
Note
Although DDoS Protection Plan resources needs to be associated with a region, users can enable DDoS protection on Virtual Networks in different regions and across multiple subscriptions under a single Microsoft Entra tenant.
Reference:
https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection
https://learn.microsoft.com/en-us/answers/questions/951433/how-to-protect-azure-webapp-from-denial-of-service
https://www.examtopics.com/exams/microsoft/az-500/view/29/#
"Directly adding DDoS protection to an individual web app is not possible, but you can protect your web apps indirectly by protecting the underlying infrastructure."
It means, Web app can be protected, but not directly. Only with WAF.
To support the answer:
No, an Azure DDoS Protection Plan (like the one named DDoS1) cannot be directly added to an Azure Web App in the West US region or any other region. This is because Azure DDoS Protection is designed to protect resources deployed within virtual networks, such as virtual machines, load balancers, or application gateways. Azure Web Apps, on the other hand, are part of the App Service platform and do not reside within a virtual network by default.
Answer: C
C. VNet1 and VNet2 only
Explanation:
Azure DDoS Protection is designed to protect Virtual Networks (VNets), not individual web applications like Azure Web Apps (App Services).
DDoS Protection Plans can only be linked to VNets.
Web App Services (like WebApp1) are PaaS services and are not directly protected by DDoS Protection Plans. Instead, Azure Web Apps are automatically protected by Azure’s built-in global DDoS protection, but they cannot be linked to a DDoS Protection Plan.
VNets in any region can be linked to a DDoS Protection Plan, even if they are in different regions than the plan itself. So, even though DDoS1 is in West US, you can still add VNet2 from East US to it.
Resource Analysis:
VNet1 (West US) → ✅ Can be added.
VNet2 (East US) → ✅ Can be added.
WebApp1 (West US) → ❌ Cannot be added (Azure Web Apps are not VNet-dependent and are not protected by DDoS Protection Plans).
Tested in lab
created a ddos plan and the only protected resources I could select are
vnet, firewall, application gateway, bastion host, load balancer, NIC, VMSS, and vnet gateway.
No option for a webapp directly, Only via the app gateway
"A DDoS protection plan defines a set of virtual networks that have DDoS Network Protection enabled ... Although DDoS Protection Plan resources needs to be associated with a region, users can enable DDoS protection on Virtual Networks in different regions"
https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection
(For DDoS protection of a Web App, you need WAF, not a "DDoS Protection Plan".)
I think here answer is C as in order to add DDOS protection to Web App we should have application gateway deployed to the vnet but here we can not talk about WAF deployed that is why I would go with C.
Enable DDOS Protection Standard on the virtual network hosting your App Service's Web Application Firewall. Azure provides DDoS Basic protection on its network, which can be improved with intelligent DDoS Standard capabilities which learns about normal traffic patterns and can detect unusual behavior. DDoS Standard applies to a Virtual Network so it must be configured for the network resource in front of the app, such as Application Gateway or an NVA.
https://learn.microsoft.com/en-us/security/benchmark/azure/baselines/app-service-security-baseline
BR
Agreed, "or web applications protection at layer 7, you need to add protection at the application layer using a WAF offering. For more information, see Application DDoS protection."
A DDoS protection plan defines a set of virtual networks that have DDoS Network Protection enabled, across subscriptions.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.AZ-500 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
chiquito
Highly Voted 1 year, 1 month agoschpeter_091
5 months, 1 week agoITFranz
Most Recent 3 weeks, 6 days agogolitech
3 months agoJBAnalyst
4 months, 2 weeks agoegore_E3
5 months, 2 weeks agopentium75
9 months, 1 week agoPillartech
9 months, 2 weeks agoJimmy500
10 months, 1 week ago93b98ea
10 months agoRaphaelG
11 months agoe2b11ca
1 year ago