certslothcertsloth
AZ-700/Topic 04

Azure / Associate

Application Delivery and Network Security

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Choose the traffic layer, then preserve origin access, TLS and inspection symmetry.

Must remember

  • Load Balancer handles Layer 4 flows; Application Gateway handles regional HTTP/S routing; Front Door handles global HTTP/S delivery. Configure backend pools/origin groups, probes, rules and failover priorities according to the selected product.
  • Host/path routing needs correct host headers and backend TLS/SNI. Front Door origins should reject unwanted bypass paths using supported origin-access controls. Caching requires deliberate keys, TTL and invalidation; never cache personalised responses as shared public content.
  • WAF managed/custom/rate-limit rules inspect web requests; choose detection/prevention and exclusions based on observed false positives. Azure Firewall supports network/application rules and SKU-specific capabilities; policy hierarchy and rule processing order matter. NSGs filter connections at subnet/NIC scopes.
  • DDoS protection addresses volumetric/network attacks under the selected plan; it does not replace WAF or secure application logic. Network Manager can centrally manage supported connectivity/security configurations; staged rollout avoids widespread incorrect routing.
  • Private Link service exposes supported provider services through consumer private endpoints. Approvals, endpoint subresources, DNS and backend configuration all matter. Service endpoints are a different mechanism and still use service public endpoints with network identity/rules.
  • Centralised inspection must handle symmetric stateful flows and zone failures. TLS inspection requires a supported SKU/configuration, certificate trust and a reasoned exception policy. Do not assume encrypting traffic means a firewall can inspect its application payload.

Choose under exam pressure

Requirement Choice and reason
Block malicious HTTP payload patterns WAF on a supported application delivery service.
Inspect outbound destination domains Appropriate Firewall application rules and DNS design.
Expose a specific service privately to consumers Private Link service/endpoints where supported.

Traps

  • TLS termination and end-to-end TLS are different designs.
  • A health probe can succeed while the requested host/path fails.
  • A firewall can be bypassed by an unintended alternate route.

Active recall

1. Which layer is Application Gateway primarily designed for?

HTTP/S application-layer routing.

2. Why restrict direct origin access behind Front Door?

Otherwise clients can bypass intended edge controls.

3. What should WAF exclusions be based on?

A narrow understood false positive, tested against the security requirement.

4. Why does inspection need symmetry?

Stateful devices must observe a coherent connection flow.

5. What remains necessary after private endpoint approval?

Correct DNS, routing, service configuration and data authorisation.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.