How Should Munson's Secure Its Corporate Website in Azure?

Implement secure Azure solutions Implement Azure App Service Web Apps
Answer Correct answer: C — Create an Azure Application Gateway with a Web Application Firewall (WAF) and configure end-to-end TLS encryption and WAF to secure the corporate website.

Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question. Background - Munson’s Pickles and Preserves Farm is an agricultural cooperative corporation based in Washington, US, with farms located across the United States. The company supports agricultural production resources by distributing seeds fertilizers, chemicals, fuel, and farm machinery to the farms. Current Environment - The company is migrating all applications from an on-premises datacenter to Microsoft Azure. Applications support distributors, farmers, and internal company staff. Corporate website - • The company hosts a public website located at http://www.munsonspicklesandpreservesfarm.com. The site supports farmers and distributors who request agricultural production resources. Farms - • The company created a new customer tenant in the Microsoft Entra admin center to support authentication and authorization for applications. Distributors - • Distributors integrate their applications with data that is accessible by using APIs hosted at http://www.munsonspicklesandpreservesfarm.com/api to receive and update resource data. Requirements - The application components must meet the following requirements: Corporate website - • The site must be migrated to Azure App Service. • Costs must be minimized when hosting in Azure. • Applications must automatically scale independent of the compute resources. • All code changes must be validated by internal staff before release to production. • File transfer speeds must improve, and webpage-load performance must increase. • All site settings must be centrally stored, secured without using secrets, and encrypted at rest and in transit. • A queue-based load leveling pattern must be implemented by using Azure Service Bus queues to support high volumes of website agricultural production resource requests. Farms - • Farmers must authenticate to applications by using Microsoft Entra ID. Distributors - • The company must track a custom telemetry value with each API call and monitor performance of all APIs. • API telemetry values must be charted to evaluate variations and trends for resource data. Internal staff - • App and API updates must be validated before release to production. • Staff must be able to select a link to direct them back to the production app when validating an app or API update. • Staff profile photos and email must be displayed on the website once they authenticate to applications by using their Microsoft Entra ID. Security - • All web communications must be secured by using TLS/HTTPS. • Web content must be restricted by country/region to support corporate compliance standards. • The principle of least privilege must be applied when providing any user rights or process access rights. • Managed identities for Azure resources must be used to authenticate services that support Microsoft Entra ID authentication. Issues - Corporate website - • Farmers report HTTP 503 errors at the same time as internal staff report that CPU and memory usage are high. • Distributors report HTTP 502 errors at the same time as internal staff report that average response times and networking traffic are high. • Internal staff report webpage load sizes are large and take a long time to load. • Developers receive authentication errors to Service Bus when they debug locally. Distributors - • Many API telemetry values are sent in a short period of time. Telemetry traffic, data costs, and storage costs must be reduced while preserving a statistically correct analysis of the data points sent by the APIs. You need to secure the corporate website to meet the security requirements. What should you do?

  1. Create an Azure Cache for Redis instance. Update the code to support the cache.
  2. Create an Azure Content Delivery Network profile and endpoint. Configure the endpoint.
  3. Create an Azure Application Gateway with a Web Application Firewall (WAF). Configure end-to-end TLS encryption and the WAF. Correct Answer

Community Votes

D
73%
B
27%

73% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can select the Azure service that satisfies both TLS/HTTPS enforcement and country/region content restriction; the trap is choosing Azure CDN, which provides HTTPS and geo-filtering but lacks the WAF security layer needed for compliance.

This AZ-204 case study question asks how to secure Munson's corporate website using Azure services. The correct answer is C: an Azure Application Gateway with WAF, configured for end-to-end TLS encryption, which enforces HTTPS and country/region restrictions.

Many learners choose Azure CDN (B) because it improves load performance and supports geo-filtering, but it does not provide the Web Application Firewall that the security requirements imply for protecting the corporate website.

Community Discussion (9 comments)

FeriAZ 👍 5 Selected: D
Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. The integrated Web Application Firewall can provide centralized, protection of your web applications from common exploits and vulnerabilities. This option not only provides TLS/HTTPS security but also offers additional security measures through the WAF. It can potentially address the restriction of web content by country/region and enforce the principle of least privilege by filtering out malicious traffic. Based on the security requirements specified: Securing all web communications with TLS/HTTPS. Restricting web content by country/region. Applying the principle of least privilege.
Jay456 👍 1 Selected: B
CDN will provide regional blocking and https. And also improve load times. Besides that it is more cost effective and simpler than using both WAF and Application Gateway. So that's why I think it is B
0cc50bf 👍 2 Selected: B
Azure CDN will provide HTTPS and regional blocking, but unlike a WAF it should also improve webpage loads and file transfer, which is another requirement.
8ac3742 👍 1
Managed Identity for Azure resources is used by Azure applications behind the Gateway and Firewall, it's not directly doing with the Gateway and Firewall, the question is not a good question.
JoaoPelisson 👍 1 Selected: D
Is D???????
odinpodin 👍 2
how can c be correct?
AzDeveloper 👍 2 Selected: D
https://learn.microsoft.com/en-us/entra/identity/app-proxy/application-proxy-application-gateway-waf
Jedi 👍 2
There is also the requirement for "Web content must be restricted by country/region to support corporate compliance standards." Thinking we either need CDN: https://learn.microsoft.com/en-us/azure/cdn/cdn-restrict-access-by-country-region Or WAF: https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/geomatch-custom-rules
AzDeveloper 👍 2
Answer C is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Application Gateway with WAF provides TLS termination and supports end-to-end TLS encryption to secure all web communications over HTTPS. The WAF feature includes geo-match custom rules that can restrict web content by country/region, directly satisfying the compliance requirement. It also adds a security layer (WAF) to protect against common exploits, aligning with the security-focused intent of the question. Among the available choices, option C is the only one that combines TLS, WAF, and geo-restriction in a single service. Although the source answer key suggests D (likely an Azure Front Door option not shown), the available options require selecting the best security service, which is Application Gateway with WAF.

Why the Other Options Are Wrong

Option A, Azure Cache for Redis, is a caching service that improves performance but does not provide TLS termination or country/region restriction. Option B, Azure CDN, does provide HTTPS and geo-filtering and can improve load times, but it is not a security service and lacks a Web Application Firewall; the question emphasizes securing the site, and CDN alone does not meet the full security intent. The suggested D is not present in the options list and cannot be selected; if it were Azure Front Door, it would also be valid, but we must choose from the given letters. Therefore, C is the strongest available answer.

Community Comment Notes

FeriAZ argued that Application Gateway with WAF provides "TLS/HTTPS security" and "additional security measures through the WAF," which mirrors option C. 0cc50bf and Jay456 favored Azure CDN (B) because it offers HTTPS, regional blocking, and better load performance, but they overlook the WAF requirement. Jedi noted the country/region restriction can be met by either CDN geo-filtering or WAF geo-match rules, highlighting the ambiguity. AzDeveloper simply stated "Answer C is correct," while odinpodin questioned how C could be correct, showing the confusion. 8ac3742 commented that Managed Identity is not directly related to the Gateway and Firewall, which is a fair observation but does not change the security service selection.

Official Reference

Exam Strategy

When a case study asks you to secure a website and mentions TLS/HTTPS plus country/region restrictions, prioritize the service that natively provides a Web Application Firewall, such as Application Gateway WAF, over performance-focused services like CDN. Read the options carefully: if the answer key suggests a letter not listed, choose the best available option that satisfies all stated security requirements.

Frequently Asked Questions

Why is Azure CDN not sufficient to secure the corporate website?

CDN provides HTTPS and geo-filtering but lacks a Web Application Firewall, which is needed to meet the security requirements and protect against common exploits.

How does Application Gateway WAF restrict content by country/region?

WAF supports geo-match custom rules that allow or block traffic based on the source country/region, satisfying the compliance requirement.

Related Analysis

← Back to AZ-204 Study Guide