You have an Application Gateway with the Web Application Firewall (WAF) enabled. The gateway is configured to route traffic to its own URL, but when you try to open that URL you receive HTTP 403 and the diagnostics indicate WAF blocking. You need the URL to be reachable through the application gateway from any client IP. The proposed solution is to configure a custom cookie and add an exclusion rule. Does this solution achieve the requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: No.
Why this is the answer
Configuring a custom cookie and adding an exclusion rule would not resolve the issue. Exclusion rules allow you to omit certain request attributes (like headers, cookies, or query string arguments) from WAF inspection, but they do not bypass the WAF entirely for a specific URL or allow traffic based on a custom cookie. The problem states that the Application Gateway is routing traffic to its own URL, which suggests a potential loop or misconfiguration where the WAF is blocking its own health probes or requests. A more appropriate solution would involve reviewing the WAF logs to identify the specific rule being triggered and then either disabling that rule (if it's a false positive) or creating a custom rule to allow the necessary traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed