← SC-900: security, identity, and operational decisions
03 / 6 · 30 MIN

Infrastructure protection

Distinguish network controls, web applications, and sensitive material.

Concept and mechanism

Controls with similar names act on different surfaces. An NSG allows or denies traffic using network properties and retains connection state. It does not interpret a SQL injection expression in an HTTP request as a WAF does. Azure Firewall can support central network policies; WAF protects web applications against attack patterns. DDoS protection addresses availability during network attacks, with scope and plan to confirm. These capabilities can complement each other without removing the need for secure code, identity management, and correct configuration. Draw the actual traffic path to identify where each control applies. A product outside that path does not provide the protection suggested by a diagram.

Guided application

For a fictional funds portal, separate customer traffic from administrative access. Bastion can connect to VMs over private addresses; its SKU and own requirements need validation. Do not interpret this as absence of every public IP in every possible design. During an intervention, removing an NSG rule does not necessarily terminate an existing session; test a new connection too. For keys, secrets, and certificates, Key Vault provides central management with access control. Inventory consumers and dependencies before rotating sensitive material. Placing a credential in a vault neither invalidates previously exposed copies nor guarantees the application uses the intended version.

IN PRACTICE

The old SSH session continues; the new one fails. That can match a stateful NSG.

Common pitfalls

WAF as every-protocol filtering; old session as proof of the current rule; vault storage as copy revocation.

Related topics: Posture, detection, and response · Classification, DLP, and retention

Take this idea with you

Choose controls by surface and validate actual behavior.

Create account

Reference: Network security groups · SC-900 objectives 2026-07-28; October 2026 update announced