SC-900 - Microsoft Security Solutions - Section 3.1

Describe core infrastructure security services in Azure.

Describe Azure DDoS Protection, Azure Firewall, web application firewall, and network security groups as layered network controls, and explain how Azure Bastion provides secure RDP and SSH access without exposing public IP addresses. Recognise Azure Key Vault as the service used to centralise storage and access control for secrets, keys, and certificates.

Azure DDoS ProtectionAzure Firewallweb application firewallnetwork security groupsAzure BastionAzure Key Vault

Practice question for this objective

Free sampleMicrosoft Security Solutionsmedium

An architect is mapping Azure perimeter controls and must match each protective need to the correct service. Which TWO pairings of an Azure security service with the threat it is designed to address are correct? Select TWO.

  • AAzure Bastion defends storage accounts against malware uploaded by users to file shares.
  • BAzure DDoS Protection defends public endpoints against volumetric traffic floods that exhaust resources. Correct
  • CNetwork security groups defend applications by detonating email attachments in a sandbox.
  • DWeb application firewall defends web apps against common exploits such as SQL injection and cross-site scripting. Correct
  • EAzure Key Vault defends virtual machines by recording administrative RDP and SSH sessions.
Distinct Azure perimeter services address distinct threats: DDoS Protection covers floods and a web application firewall covers common web application exploits. DDoS Protection mitigates volumetric flood attacks against public endpoints, while a WAF inspects HTTP traffic for exploits such as injection and cross-site scripting. Bastion, NSGs and Key Vault solve different problems, so the remaining pairings misassign each service.

Why A is wrong: Bastion brokers RDP and SSH to VMs; storage malware scanning is a Defender for Storage capability, not Bastion.

Why B is correct: DDoS Protection is purpose-built to detect and mitigate volumetric, protocol, and resource-exhaustion flood attacks.

Why C is wrong: Attachment detonation is Defender for Office 365 Safe Attachments; NSGs only filter network traffic flows.

Why D is correct: A WAF inspects HTTP traffic and blocks OWASP-class web exploits like injection and scripting attacks.

Why E is wrong: Session recording is an Azure Bastion premium feature; Key Vault stores secrets, keys and certificates only.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Microsoft Security Solutions objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.