An Azure Front Door instance FD1, protected by Azure Web Application Firewall (WAF), uses the frontend host app1.contoso.com to front Azure web apps hosted in East US and West US. You need to configure FD1 so that requests to app1.contoso.com are blocked from all countries except the United States. What should you add to the WAF policy?
Choose an answer
Tap an option to check your answer.
Correct answer: a custom rule that uses a match rule.
Why this is the answer
To block requests from all countries except the United States, you need to create a custom WAF rule. This rule will use a "match rule" to evaluate the geographic location of the request based on the client's IP address. You would configure the match condition to check the "Country" field and specify "United States" as the allowed value, with an action to "Block" for all other countries. A "frontend host association" is used to link a WAF policy to a specific frontend host, but it doesn't define the blocking logic itself. A "rate limit rule" is used to restrict the number of requests from a single IP address over a period, not for geo-blocking. A "managed rule set" provides pre-configured protection against common threats but doesn't offer the granular control needed for specific country-based access restrictions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed