AZ-900

Azure Network Security

Network Security Groups

NSG is a static set of rules which protects the network, also known as Access Control List. Certain IPs will have access to certain ports only, It is deny by default. A virtual network can be divided into subnets, we can have public facing services on a separate subnet and the critical back end services on a more protected subnet.

Azure Firewall

An intelligent traffic analysis tool that matches incoming traffic to see if it matches certain bad patterns like SQL injection, CORS etc.

Azure DDoS Protection