Topic module

Azure Firewall, Firewall Manager and WAF

This topic covers Azure Firewall SKUs, rules, policies, secured virtual hubs, Firewall Manager, Web Application Firewall, detection and prevention, and policy association.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-700

Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.

Core concepts

Concept 1

Azure Firewall, Firewall Manager and WAF questions test Azure networking design and troubleshooting choices rather than memorized portal paths.

Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.

Concept 2

The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.

Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.

Concept 3

Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.

Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.

Risk pitfalls and guardrails

Confusing DNS resolution with routing or security filtering.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Memory anchors

Azure Firewall

Azure Firewall is a managed network security service for filtering, logging, and controlling traffic.

Firewall Policy

A firewall policy centrally manages Azure Firewall rules and settings.

DNAT Rule

A DNAT rule translates inbound traffic to reach internal resources through the firewall.

Network Rule

A network rule filters traffic by source, destination, protocol, and port.

Application Rule

An application rule filters outbound HTTP, HTTPS, or SQL traffic by FQDN and protocol.

Threat Intelligence

Threat intelligence filtering can alert on or deny traffic to known malicious IPs and domains.

Firewall Manager

Azure Firewall Manager centrally manages firewall policies and secured virtual hubs.

Secured Virtual Hub

A secured virtual hub integrates Azure Firewall with Virtual WAN for centralized security.

WAF Policy

A Web Application Firewall policy protects web applications from common HTTP attacks.

Prevention Mode

WAF prevention mode blocks requests that match configured rules rather than only logging them.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A hub-and-spoke design requires centralized, stateful filtering for traffic between spokes and to the Internet. Which Azure service is designed for this?

Which subnet name is reserved for an Azure Firewall deployment in a VNet?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.