SC-900 - Microsoft Security Solutions (38% of the exam) - Section 3.1

Describe core infrastructure security services in Azure.

Describe Azure DDoS Protection, Azure Firewall, web application firewall, and network security groups as layered network controls, and explain how Azure Bastion provides secure RDP and SSH access without exposing public IP addresses. Recognise Azure Key Vault as the service used to centralise storage and access control for secrets, keys, and certificates.

Azure DDoS ProtectionAzure Firewallweb application firewallnetwork security groupsAzure BastionAzure Key Vault

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

An architect is mapping Azure perimeter controls and must match each protective need to the correct service. Which TWO pairings of an Azure security service with the threat it is designed to address are correct? Select TWO.

  • AAzure Bastion defends storage accounts against malware uploaded by users to file shares.
  • BAzure DDoS Protection defends public endpoints against volumetric traffic floods that exhaust resources. Correct
  • CNetwork security groups defend applications by detonating email attachments in a sandbox.
  • DWeb application firewall defends web apps against common exploits such as SQL injection and cross-site scripting. Correct
  • EAzure Key Vault defends virtual machines by recording administrative RDP and SSH sessions.
Distinct Azure perimeter services address distinct threats: DDoS Protection covers floods and a web application firewall covers common web application exploits. DDoS Protection mitigates volumetric flood attacks against public endpoints, while a WAF inspects HTTP traffic for exploits such as injection and cross-site scripting. Bastion, NSGs and Key Vault solve different problems, so the remaining pairings misassign each service.

Why A is wrong: Bastion brokers RDP and SSH to VMs; storage malware scanning is a Defender for Storage capability, not Bastion.

Why B is correct: DDoS Protection is purpose-built to detect and mitigate volumetric, protocol, and resource-exhaustion flood attacks.

Why C is wrong: Attachment detonation is Defender for Office 365 Safe Attachments; NSGs only filter network traffic flows.

Why D is correct: A WAF inspects HTTP traffic and blocks OWASP-class web exploits like injection and scripting attacks.

Why E is wrong: Session recording is an Azure Bastion premium feature; Key Vault stores secrets, keys and certificates only.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Security Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Azure Firewall, which is a stateful network firewall service for filtering network traffic.

    Why it is wrong: Azure Firewall filters network traffic to and from workloads, but it does not provide RDP or SSH connectivity to virtual machines, so it does not fit this scenario.

  • Azure Firewall, which is a cloud-native stateful network firewall for filtering network traffic.

    Why it is wrong: Azure Firewall filters network traffic and does not store application secrets such as connection strings or passwords.

  • Virtual network inbound and outbound traffic rules applied to subnets and interfaces.

    Why it is wrong: Traffic rules belong to network security groups; Key Vault stores cryptographic material, not network filtering policy.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.