Your subscription has three public IPs: one on Application Gateway v2 for a customer portal, one on a Standard Load Balancer for AKS, and one test IP. Budget is limited. You must protect only the two critical IPs against volumetric DDoS attacks and obtain attack metrics and mitigation reports. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable DDoS IP Protection on the two critical public IP resources and stream DDoS diagnostic logs and metrics to Log Analytics for reporting..
Why this is the answer
DDoS IP Protection is the correct choice because it offers dedicated protection for specific public IP addresses, which aligns with the requirement to protect only the two critical IPs. This tier also provides attack metrics and mitigation reports, fulfilling the reporting requirement. Streaming diagnostic logs to Log Analytics is the standard method for collecting and analyzing these reports. DDoS Network Protection protects an entire VNet, which would be overkill and more expensive than necessary for only two IPs. Relying on Basic DDoS protection is insufficient as it doesn't provide the required metrics or guaranteed mitigation for volumetric attacks. WAF on Application Gateway primarily handles L7 attacks, not volumetric L3/4 DDoS. Azure Front Door can provide DDoS protection, but it's a global service that might be more complex or costly than needed if only IP-level protection is required for existing resources. Azure Monitor alone does not mitigate DDoS attacks; it's a monitoring service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed