exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 3 question 13 discussion

Actual exam question from Microsoft's SC-100
Question #: 13
Topic #: 3
[All SC-100 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance.
You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.
Solution: You recommend access restrictions that allow traffic from the Front Door service tags.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mikenyga
Highly Voted 2 years, 7 months ago
Answer correct. You need to recommend a solution to ensure that the web apps only allow access through the Front Door (INSTANCE) this is important! Restrict access to a specific Azure Front Door instance with X-Azure-FDID header restriction
upvoted 30 times
TP447
2 years, 4 months ago
Agree. Service Tag would allow for multiple instances so need the specific headers of the Front Door instance to comply with this requirement.
upvoted 4 times
Jt909
2 years, 3 months ago
Exactly. Docs info are here https://learn.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions?tabs=azurecli#restrict-access-to-a-specific-azure-front-door-instance
upvoted 6 times
...
...
...
BillyB2022
Highly Voted 2 years, 7 months ago
Selected Answer: A
Service Tags
upvoted 10 times
...
sweetykaur
Most Recent 2 months, 2 weeks ago
Selected Answer: A
Yes, it meets the goal. Recommending access restrictions that allow traffic from the Azure Front Door service tags ensures that only traffic coming from the Front Door instance is allowed to access your Azure App Service web apps. This effectively secures the web apps by limiting access to traffic that has been routed and potentially inspected by Azure Front Door, minimizing the risk of direct malicious attacks.
upvoted 1 times
...
Ali96
2 months, 3 weeks ago
Selected Answer: A
the correct answer is: A. Yes
upvoted 1 times
...
Gythms
8 months ago
Selected Answer: B
Service Tags with X-Azure-FDID header restriction
upvoted 2 times
...
jayek
10 months, 2 weeks ago
https://learn.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions?tabs=powershell#restrict-access-to-a-specific-azure-front-door-instance:~:text=Restrict%20access%20to%20a%20specific,that%20Azure%20Front%20Door%20sends.
upvoted 1 times
...
aks_exam
1 year, 2 months ago
Yes, allowing traffic only from the Azure Front Door service tag as an access restriction ensures that a Web App only allows access through a Front Door instance. This is because Front Door's features work best when traffic only flows through Front Door.
upvoted 1 times
...
lt9898
1 year, 2 months ago
Selected Answer: B
Agree with those making the distinction of the question specifying the 'instance'. Service tags is not enough without validation of the X-Azure-FDID header to lock access to the specific instance. Voting to help sway the confusion in the right direction.
upvoted 4 times
...
Murtuza
1 year, 3 months ago
Selected Answer: B
B is the correct choice
upvoted 1 times
...
Arockia
1 year, 3 months ago
To securely restrict access to Azure App Service web apps through Azure Front Door, a more robust approach is required: 1. Service Tag-Based Access Restrictions 2. Custom Headers
upvoted 3 times
...
Ario
1 year, 9 months ago
Selected Answer: A
By configuring access restrictions to allow traffic from the Front Door service tags, you can effectively restrict access to the web apps only from the Front Door instance. This approach provides a reliable and scalable solution since the Front Door service tags automatically adapt to any changes in IP ranges associated with the Front Door service.
upvoted 2 times
...
imsidrai
1 year, 10 months ago
Restrict access to a specific Azure Front Door instance Traffic from Azure Front Door to your application originates from a well known set of IP ranges defined in the AzureFrontDoor.Backend service tag. Using a service tag restriction rule, you can restrict traffic to only originate from Azure Front Door. To ensure traffic only originates from your specific instance, you need to further filter the incoming requests based on the unique http header that Azure Front Door sends called X-Azure-FDID. You can find the Front Door ID in the portal
upvoted 1 times
...
PrettyFlyWifi
1 year, 11 months ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/frontdoor/origin-security?pivots=front-door-standard-premium&tabs=app-service-functions#public-ip-address-based-origins
upvoted 2 times
...
zellck
1 year, 11 months ago
Same as Question 14. https://www.examtopics.com/discussions/microsoft/view/79383-exam-sc-100-topic-4-question-14-discussion
upvoted 1 times
...
zellck
1 year, 11 months ago
Selected Answer: B
B is the answer. https://learn.microsoft.com/en-us/azure/app-service/overview-access-restrictions#restrict-access-to-a-specific-azure-front-door-instance Traffic from Azure Front Door to your application originates from a well known set of IP ranges defined in the AzureFrontDoor.Backend service tag. Using a service tag restriction rule, you can restrict traffic to only originate from Azure Front Door. To ensure traffic only originates from your specific instance, you need to further filter the incoming requests based on the unique http header that Azure Front Door sends called X-Azure-FDID. You can find the Front Door ID in the portal.
upvoted 1 times
...
uffman
1 year, 12 months ago
Selected Answer: B
I would select B, since it states allow connection from the Front Door instance (specific?).
upvoted 2 times
...
Fal991l
2 years, 1 month ago
Selected Answer: A
ChatGTP: A. Yes Restricting access to Azure App Service web apps to only allow traffic from the Front Door instance is a good security practice to ensure that the web apps are only accessible through the Front Door instance. One way to achieve this is by using access restrictions that allow traffic from the Front Door service tags. Azure Front Door service tags represent the IP addresses of the Front Door edge nodes, which can be used to restrict access to the web apps. By configuring access restrictions that only allow traffic from the Front Door service tags, you can ensure that the web apps are only accessible through the Front Door instance. Therefore, the recommended solution to ensure that the web apps only allow access through the Front Door instance by using access restrictions that allow traffic from the Front Door service tags meets the goal.
upvoted 2 times
imsidrai
1 year, 10 months ago
GPT is BS in such scenarios
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago