nerdexam
Microsoft

AZ-900 · Question #8

You have an Azure environment that contains 10 virtual networks and 100 virtual machines. You need to limit the amount of inbound traffic to all the Azure virtual networks. What should you create?

The correct answer is D. one Azure firewall. You can restrict traffic to multiple virtual networks with a single Azure firewall. Azure Firewall is a managed, cloud-based network security service that protects your Azure Network resources. It's a fully stateful firewall as a service with built-in high availability and unrest

Submitted by anjalisingh· Mar 5, 2026Describe Azure architecture and services

Question

You have an Azure environment that contains 10 virtual networks and 100 virtual machines. You need to limit the amount of inbound traffic to all the Azure virtual networks. What should you create?

Options

  • Aone network security group (NSG)
  • B10 virtual network gateways
  • C10 Azure ExpressRoute circuits
  • Done Azure firewall

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    9% (4)
  • D
    84% (37)

Explanation

You can restrict traffic to multiple virtual networks with a single Azure firewall. Azure Firewall is a managed, cloud-based network security service that protects your Azure Network resources. It's a fully stateful firewall as a service with built-in high availability and unrestricted cloud scalability. You can centrally create, enforce, and log application and network connectivity policies across subscriptions and virtual networks. Azure Firewall uses a static public IP address for your virtual network resources allowing outside firewalls to identify traffic originating from your virtual network. https://docs.microsoft.com/en-us/azure/firewall/overview

Community Discussion

No community discussion yet for this question.

Full AZ-900 Practice