Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage an Azure Application Gateway v2 that is configured with a Web Application Firewall (WAF) policy in Prevention mode. The security team wants to allow traffic that originates from the on-premises public IP range 131.10.50.0/24 to bypass all WAF inspections, while the existing OWASP managed rule set must remain enforced for every other request. What should you do to meet this requirement?

  • Attach a Network Security Group to the Application Gateway subnet and permit the 131.10.50.0/24 range.

  • Add a high-priority custom Match rule that allows requests when the client IP address falls within 131.10.50.0/24.

  • Change the WAF policy mode from Prevention to Detection for the Application Gateway.

  • Create a WAF exclusion list that specifies the 131.10.50.0/24 address range.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot