Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage two Azure Firewall instances named FW-EUS and FW-WEU that are deployed in separate subscriptions. Both firewalls must enforce a common set of deny rules, however each regional team needs to add its own additional rules that can override or extend the common set without editing the shared rules directly. You want the solution to be centrally managed and require the least administrative effort going forward.
Which approach should you implement?
Create an IP Groups resource for shared addresses and reference it in separate firewall rule collections configured individually on each firewall.
Attach the same standalone Azure Firewall Policy that contains both common and regional rules directly to both firewalls and update it whenever a region needs changes.
Create a single Azure Firewall Policy that contains the common rules, then create a child Firewall Policy for each region and associate each child policy with its respective firewall.
Use Azure Policy to deploy identical Network Security Groups (NSGs) with deny rules to the subnets that host the firewalls, and let each region modify the NSGs as required.
Azure Firewall Policy supports hierarchical inheritance. You create one "base" policy that contains the organization-wide rules and then create one child policy per firewall. The child policy is linked to the base policy (parent) and is associated with the firewall that it should protect. Each regional team can add or change rules only in its own child policy. Because a child policy sits closer to the firewall, its rules take precedence over identical rules in the parent, providing the required ability to override while still inheriting the common rule set. Deploying independent policies or using NSGs does not give you rule inheritance, and Azure Policy cannot express firewall rules at this level of granularity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure Firewall Policy?
Open an interactive chat with Bash
How does rule inheritance work in Azure Firewall Policy?
Open an interactive chat with Bash
Why is Azure Firewall Policy recommended over network security groups (NSGs) for this scenario?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .