Azure Firewall is a service that …

👨‍🦱 💬 Azure Firewall allows customers to filter both inbound and outbound traffic for Azure Virtual Network resources.

Which Azure services can be used to filter the traffic based on network protocol and/or IP address? Choose 2.

👨‍🦱 💬 Both Azure Firewall and Network Security Groups allow for filtering of networking traffic based on protocol and IP address.

By default all traffic through the firewall is blocked, a rule has to be added in order to enable traffic flow. True or false?

👨‍🦱 💬 This is true. When provisioned, Azure Firewall will block all traffic because the default rule is set to ‘deny’.

Conotoso company wants to block all traffic to the internet websites from their network with exception of domain names like and For that they want to use Network Security Groups, will it solve their challenge?

👨‍🦱 💬 No, Azure NSGs do not offer features for creating rules based on FQDN (fully qualified domain name). Contoso should use Azure Firewall.
