GregLab | Exam Prep

Describe the capabilities of Microsoft security solutions

Azure Infrastructure Security

Core

Match DDoS, firewall, WAF, segmentation, NSGs, Bastion, and Key Vault to their boundaries.

Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.

Why this matters

Azure infrastructure security is layered. Availability attacks, network flows, web exploits, administrative access, segmentation, and secret storage require different controls.

Must Know

  • Azure DDoS Protection helps defend public IP resources against distributed denial-of-service attacks and complements application-layer protection.
  • Azure Firewall is a managed, centralized, stateful network security service that filters network and application traffic.
  • Azure Web Application Firewall (WAF) protects web applications from common HTTP and HTTPS exploits and can be placed with Azure Application Gateway or Azure Front Door.
  • Azure virtual networks and subnets provide private network boundaries and segmentation for Azure resources.
  • Network security groups filter inbound and outbound network traffic using rules applied to supported subnets and network interfaces.
  • Azure Bastion provides RDP and SSH connectivity to virtual machines through the Azure platform without requiring public IP addresses on those VMs.
  • Azure Key Vault safeguards secrets, cryptographic keys, and certificates and supports controlled access to them.

Compare and Distinguish

  • DDoS Protection vs WAF: network-layer availability attacks versus application-layer web exploits.
  • Azure Firewall vs NSG: centralized managed inspection and filtering versus distributed allow/deny rules at subnet or network-interface scope.
  • Virtual network/subnet vs NSG: segmentation boundary versus traffic-filtering rules applied to supported network scopes.
  • Azure Bastion vs exposing RDP/SSH: managed private VM connectivity versus placing management ports on a public IP.
  • Key Vault vs a general storage account: protected secret, key, and certificate management versus general data storage.

Scenario examples

  • A public workload combines DDoS Protection for large-scale network attacks with WAF for malicious web requests.
  • A hub network uses Azure Firewall for centralized filtering while workload subnets use NSGs for local traffic rules.
  • An administrator reaches a private VM through Azure Bastion without assigning the VM a public IP.

Exam traps

  • WAF is not a general-purpose network firewall for every protocol.
  • An NSG does not provide the same centralized managed firewall capabilities as Azure Firewall.
  • Segmentation alone does not define every allowed flow; traffic controls still matter.
  • Key Vault stores protected secrets and keys; it is not the place to store ordinary application files.

Key takeaways

  • Choose controls by attack layer and scope.
  • Use VNets/subnets for segmentation and NSGs for traffic rules.
  • Use Bastion for private RDP/SSH access.
  • Keep secrets, keys, and certificates in Key Vault.

Ready for the quiz?

  • Which service targets web exploits?
  • How does an NSG differ from Azure Firewall?
  • Which service removes the need for a VM public IP during RDP/SSH access?

Related objectives

  • D3.1.S1 — Describe Azure DDoS Protection
  • D3.1.S2 — Describe Azure Firewall
  • D3.1.S3 — Describe Azure Web Application Firewall (WAF)
  • D3.1.S4 — Describe network segmentation with Azure virtual networks
  • D3.1.S5 — Describe network security groups (NSGs)
  • D3.1.S6 — Describe Azure Bastion
  • D3.1.S7 — Describe Azure Key Vault

Learn more

Free Microsoft Certified: Security, Compliance, and Identity Fundamentals prep

Build focused SC-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-900 at a glance

Level
Beginner / Fundamentals
Duration
45 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-900. This lane plans only multiple-choice and multiple-response exam-style practice; no supplemental matching, ordering, or case-study exercises are planned. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Fundamentals-level scenario complexity rather than a Microsoft-published question rating.

Reference

SC-900 topics and reference map

Study links

SC-900 resources