Your Azure environment contains 10 virtual networks and 100 virtual machines. You need to limit inbound traffic to all virtual networks. What should you create?
Choose an answer
Tap an option to check your answer.
Correct answer: one Azure firewall.
Why this is the answer
An Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources. It allows you to centrally create, enforce, and log application and network connectivity policies across subscriptions and virtual networks. By deploying one Azure Firewall, you can filter inbound traffic for all 10 virtual networks effectively. Application Security Groups (ASGs) are used to group virtual machines and define network security policies based on those groups, not to limit traffic across multiple virtual networks. Virtual network gateways are used for connecting virtual networks or connecting to on-premises networks, not for filtering inbound traffic. Azure ExpressRoute circuits provide private connectivity to Azure, bypassing the public internet, but they do not inherently filter traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed