A company requires outbound TLS inspection for SaaS access and intrusion detection/prevention for east-west traffic between VNets. A central security team must enforce global rules while allowing regional teams to add exceptions. What Azure Firewall design should you recommend?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Firewall Premium with TLS inspection and IDPS enabled, using a parent Firewall Policy at the management group and region-specific child policies for local rules..
Why this is the answer
Azure Firewall Premium is the correct choice because it offers both TLS inspection for outbound SaaS access and Intrusion Detection and Prevention System (IDPS) for east-west traffic, meeting the core requirements. The hierarchical Firewall Policy structure, with a parent policy at the management group level and child policies for regional exceptions, allows the central security team to enforce global rules while granting regional teams flexibility. Azure Firewall Standard lacks TLS inspection and IDPS. Deploying Premium Firewalls in each VNet without a policy hierarchy would prevent central management and global rule enforcement. While a third-party NVA could provide these features, the question asks for an Azure Firewall design. Azure Firewall Basic does not support TLS inspection or IDPS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed