az-900 Practice Question 503
Exam: az-900
Domain: Describe cloud concepts
Topic: Describe cloud computing
Difficulty: medium
You have an Azure environment that contains 10 virtual networks and 100 virtual machines.
You need to limit the amount of inbound traffic to all the Azure virtual networks.
What should you create?
A. one application security group (ASG)
B. 10 virtual network gateways
C. 10 Azure ExpressRoute circuits
D. one Azure firewall
Answer Options
A
one application security group (ASG)
B
10 virtual network gateways
C
10 Azure ExpressRoute circuits
D
one Azure firewall
Correct Answer
D: one Azure firewall
Explanation
You can restrict traffic to multiple virtual networks with a single Azure firewall.
Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources. It's a fully stateful
firewall as a service with built-in high availability and unrestricted cloud scalability.
You can centrally create, enforce, and log application and network connectivity policies across subscriptions and virtual networks. Azure
Firewall uses a static public IP address for your virtual network resources allowing outside firewalls to identify traffic originating from your
virtual network.