exam questions

Exam AZ-204 All Questions

View all questions & answers for the AZ-204 exam

Exam AZ-204 topic 11 question 3 discussion

Actual exam question from Microsoft's AZ-204
Question #: 3
Topic #: 11
[All AZ-204 Questions]

HOTSPOT -
You need to ensure that network security policies are met.
How should you configure network security? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Valid root certificate -
Scenario: All websites and services must use SSL from a valid root certificate authority.
Box 2: Azure Application Gateway
Scenario:
✑ Any web service accessible over the Internet must be protected from cross site scripting attacks.
✑ All Internal services must only be accessible from Internal Virtual Networks (VNets)
All parts of the system must support inbound and outbound traffic restrictions.

Azure Web Application Firewall (WAF) on Azure Application Gateway provides centralized protection of your web applications from common exploits and vulnerabilities. Web applications are increasingly targeted by malicious attacks that exploit commonly known vulnerabilities. SQL injection and cross-site scripting are among the most common attacks.
Application Gateway supports autoscaling, SSL offloading, and end-to-end SSL, a web application firewall (WAF), cookie-based session affinity, URL path-based routing, multisite hosting, redirection, rewrite HTTP headers and other features.
Note: Both Nginx and Azure Application Gateway act as a reverse proxy with Layer 7 load-balancing features plus a WAF to ensure strong protection against common web vulnerabilities and exploits.
You can modify Nginx web server configuration/SSL for X-XSS protection. This helps to prevent cross-site scripting exploits by forcing the injection of HTTP headers with X-XSS protection.
Reference:
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview https://www.upguard.com/articles/10-tips-for-securing-your-nginx-deployment

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 6 months ago
Box 1: Valid root certificate Scenario: All websites and services must use SSL from a valid root certificate authority. Box 2: Azure Application Gateway Scenario: - Any web service accessible over the Internet must be protected from cross site scripting attacks. - All Internal services must only be accessible from Internal Virtual Networks (VNets).
upvoted 55 times
KingChuang
1 year, 11 months ago
On my exam 2022-12-26. Chose: Valid root certificate Azure Application Gateway
upvoted 5 times
...
[Removed]
1 year, 5 months ago
Yeah! Box 1: Answer is written inside security tab: "must use SSL from a valid root certificate authority" Must read carefully sometime to get the answer :) Box 2: nginx as service is not provided by Microsoft azure
upvoted 5 times
...
...
AlexeyG
Highly Voted 1 year, 10 months ago
Got this in 16/02/2023
upvoted 6 times
...
Archana_G
Most Recent 7 months, 1 week ago
On my exam May 11 2024 10 questions on Contoso Case study.
upvoted 2 times
...
neelkanths
7 months, 3 weeks ago
Got it on 20 April 2024...Marks > 900...All questions from examtopics 400 questions... answer is correct...
upvoted 1 times
...
BaoNguyen2411
1 year, 4 months ago
got this question on 29/06/2023
upvoted 1 times
...
BaoNguyen2411
1 year, 4 months ago
Got this question on 29/06/2023
upvoted 1 times
...
NightshadeRC
1 year, 4 months ago
Had this question today: 2023-07-26
upvoted 1 times
...
nvtienanh
2 years ago
On exam December 2, 2022
upvoted 3 times
...
coffecold
2 years, 1 month ago
The only thing is : Azure Application Gateway can only be deployed in one region. Don't know if that violates the requirements "All services must run in multiple regions. The failure of any service in a region must not impact overall application availability." Couldn't find if nginx has the same limitation either. Would go for Azure Application Gateway
upvoted 3 times
...
angrybird2007
2 years, 4 months ago
May I know what is the different between Azure Application Gateway Vs NGINX. They are similar. Why we choice Azure Application Gateway instead of NGINX?
upvoted 1 times
gmishra88
2 years, 2 months ago
Because this is Microsoft exam, just select Application gateway. But I get what you say
upvoted 3 times
...
Knightie
2 years, 3 months ago
public facing, use an official service to tank the public with Azure Application Gateway, internal calls, just casually use any nginx will do.
upvoted 1 times
...
...
Eltooth
2 years, 5 months ago
Valid root cert Azure App gateway
upvoted 3 times
...
SivajiTheBoss
2 years, 9 months ago
Correct Answer provided
upvoted 1 times
...
petitbilly
2 years, 9 months ago
Got this one 03/2022
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...