You have resources in an Azure subscription. Configure FW1 so it filters traffic that originates from VNet1 and is destined to the fully qualified domain name (FQDN) of SQLDB1. Which type of Azure Firewall rule should you create?
Choose an answer
Tap an option to check your answer.
Correct answer: application.
Why this is the answer
An application rule is the correct choice because it allows you to filter traffic based on FQDNs, HTTP/S protocols, and SQL protocols. Since the requirement is to filter traffic destined for the FQDN of SQLDB1, an application rule is necessary. DNAT (Destination Network Address Translation) rules are used for translating public IP addresses to private IP addresses for inbound connections. Network rules are used for filtering traffic based on IP addresses, ports, and protocols (TCP, UDP, ICMP, etc.), but not FQDNs. Infrastructure is not a type of Azure Firewall rule.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed