An Azure Firewall is deployed to AzureFirewallSubnet and all traffic from Subnet2 is routed through that firewall. Hosts in Subnet2 must be able to access an external site at https://*.contoso.com. Which change should you make to the firewall policy to allow this access?
Choose an answer
Tap an option to check your answer.
Correct answer: In a firewall policy, create an application rule..
Why this is the answer
To allow hosts in Subnet2 to access an external website at https://.contoso.com, you need an application rule in the Azure Firewall policy. Application rules filter traffic based on fully qualified domain names (FQDNs) and HTTP/HTTPS protocols, which is exactly what's required for web access to a specific domain. A DNAT rule is used for inbound traffic to translate public IP addresses to private ones, not for outbound web access. A network security group (NSG) is a good option for basic network-level filtering within a virtual network but lacks the FQDN-based filtering capabilities of an Azure Firewall application rule, especially for outbound web traffic. A network rule in Azure Firewall is used for filtering based on IP addresses, ports, and protocols (like TCP/UDP), but not for FQDNs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed