nerdexam
Microsoft

AZ-700 · Question #203

You have an Azure subscription that contains the resources shown in the following table. Users on HP1 connect to App1 by using a URL of https://app1.contoso.com. You need to ensure that the IDPS on…

The correct answer is A. Enable TLS inspection for FW1. B. Import a server certificate to KV1. The Firewall needs to be able to decrypt the traffic so the IDS can inspect the traffic. To do this TLS inspection needs to be enabled and a copy of the certificate needs to be stored. https://learn.microsoft.com/en-us/azure/firewall/premium-certificates…

Submitted by parkjh· Apr 18, 2026

Question

You have an Azure subscription that contains the resources shown in the following table. Users on HP1 connect to App1 by using a URL of https://app1.contoso.com. You need to ensure that the IDPS on FW1 can identify security threats in the connections from HP1 to Server1. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Exhibit

AZ-700 question #203 exhibit

Options

  • AEnable TLS inspection for FW1.
  • BImport a server certificate to KV1.
  • CEnable threat intelligence for FW1.
  • DAdd an application group to HP1.
  • EAdd a secured virtual network to FW1.

How the community answered

(34 responses)
  • A
    79% (27)
  • C
    6% (2)
  • D
    3% (1)
  • E
    12% (4)

Explanation

The Firewall needs to be able to decrypt the traffic so the IDS can inspect the traffic. To do this TLS inspection needs to be enabled and a copy of the certificate needs to be stored. https://learn.microsoft.com/en-us/azure/firewall/premium-certificates https://learn.microsoft.com/en-us/azure/firewall/premium-features#tls-inspection

Community Discussion

No community discussion yet for this question.

Full AZ-700 Practice