Unit 2: Secure Networking - Subjective Questions

INT328 — Network Virtualization And Cloud Security • Practice Questions with Detailed Answers

20 questions

1

Define an Azure Virtual Network (AVN/VNet) and explain its main components.

2

Explain how subnetting is used in an Azure Virtual Network and state its security benefits.

3

Describe the methods available for connecting an Azure Virtual Network to other networks.

4

What is a Network Security Group (NSG)? Explain the fields used in an NSG security rule.

5

Explain how Azure evaluates NSG rules when NSGs are associated with both a subnet and a network interface.

6

Distinguish between Network Security Groups, Application Security Groups, and generic cloud security groups.

7

Design NSG rules for a three-tier application containing web, application, and database subnets. Justify the design.

8

What are User-Defined Routes (UDRs)? Explain the important route properties and next-hop types.

9

Explain Azure route selection using longest prefix match, route source, and UDR priority.

10

Describe how UDRs can force outbound traffic through a centralized firewall. Include possible routing problems.

11

Explain the purpose and major capabilities of Azure Firewall.

12

Compare an NSG with Azure Firewall and explain when both should be used.

13

Describe a secure procedure for configuring and validating firewall rules in Azure.

14

Define a Web Application Firewall (WAF) and explain the types of attacks it is designed to mitigate.

15

Distinguish between WAF detection mode and prevention mode. How should an organization move safely from one mode to the other?

16

Compare deploying Azure WAF on Application Gateway with deploying it on Azure Front Door.

17

What is Azure DDoS Protection Standard, and how does it improve upon basic platform-level DDoS protection?

18

Differentiate between volumetric, protocol, and application-layer DDoS attacks, and identify suitable Azure defenses.

19

Design a defense-in-depth architecture for a public Azure web application using VNet, NSGs, UDRs, Azure Firewall, WAF, and DDoS protection.

20

Explain how logging, monitoring, and troubleshooting should be performed across NSGs, routes, Azure Firewall, WAF, and DDoS protection.