Contoso Ltd. has deployed Azure Firewall Premium in a hub virtual network to protect inbound and outbound traffic for multiple VNets. The security team must detect and block SQL injection attacks over TLS for traffic passing through the firewall. They require signature-based IDPS and TLS inspection for east-west and north-south traffic, but must not decrypt traffic to backend SQL servers that use client certificate authentication. Which configuration meets the requirement with minimal risk to client-certificate-protected flows?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable IDPS policy with signature-based detection and set TLS inspection to 'Allow list' mode; add backend SQL server FQDNs and client-certificate OIDs to the TLS inspection exclusion list..
Why this is the answer
The correct option enables signature-based IDPS for SQL injection detection and uses TLS inspection in 'Allow list' mode. This allows specific traffic to be inspected while explicitly excluding traffic to backend SQL servers that use client certificate authentication, preventing decryption of these sensitive flows. Adding the SQL server FQDNs and client-certificate OIDs to the exclusion list ensures these flows bypass TLS inspection, preserving their integrity. Incorrect options: Anomaly-based detection alone might miss known SQL injection patterns. Full TLS decryption for all traffic would break client certificate authentication. 'Inspect all' mode would also decrypt the client-certificate-protected traffic. A DNAT bypass would prevent any firewall inspection, including IDPS, for SQL traffic. Disabling IDPS rules and relying on NSG flow logs would not actively block SQL injection attacks and offers no TLS inspection.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed