Azure DDoS Protection Plan Resource Eligibility

Plan and implement security for virtual networks
Answer Correct answer: C — Only Virtual Networks (VNet1 and VNet2) can be added to an Azure DDoS Protection plan.

You have an Azure subscription that contains the resources shown in the following table. You create an Azure DDoS Protection plan named DDoS1 in the West US Azure region. Which resources can you add to DDoS1? - image

  1. VNetl1only
  2. WebApp1 only
  3. VNet1 and VNet2 only Correct Answer
  4. VNet1 and WebApp1 only
  5. VNet1, VNet2, and WebApp1

Community Votes

C
85%
E
15%

85% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of DDoS Protection plan scope; the common trap is assuming PaaS services like Web Apps can be directly protected by a DDoS plan.

Determines which Azure resources can be added to a DDoS Protection plan. The correct answer is C because DDoS Protection plans only support Virtual Networks, not individual PaaS services like Web Apps.

Many candidates choose E (VNet1, VNet2, and WebApp1) because they assume all listed resources are eligible for protection, missing that Web Apps require an Application Gateway with WAF for DDoS protection.

Community Discussion (9 comments)

chiquito 👍 11
Answer E: is correct Note Although DDoS Protection Plan resources needs to be associated with a region, users can enable DDoS protection on Virtual Networks in different regions and across multiple subscriptions under a single Microsoft Entra tenant. Reference: https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection https://learn.microsoft.com/en-us/answers/questions/951433/how-to-protect-azure-webapp-from-denial-of-service https://www.examtopics.com/exams/microsoft/az-500/view/29/#
golitech 👍 2 Selected: C
C. VNet1 and VNet2 only Explanation: Azure DDoS Protection is designed to protect Virtual Networks (VNets), not individual web applications like Azure Web Apps (App Services). DDoS Protection Plans can only be linked to VNets. Web App Services (like WebApp1) are PaaS services and are not directly protected by DDoS Protection Plans. Instead, Azure Web Apps are automatically protected by Azure’s built-in global DDoS protection, but they cannot be linked to a DDoS Protection Plan. VNets in any region can be linked to a DDoS Protection Plan, even if they are in different regions than the plan itself. So, even though DDoS1 is in West US, you can still add VNet2 from East US to it. Resource Analysis: VNet1 (West US) → ✅ Can be added. VNet2 (East US) → ✅ Can be added. WebApp1 (West US) → ❌ Cannot be added (Azure Web Apps are not VNet-dependent and are not protected by DDoS Protection Plans).
JBAnalyst 👍 4 Selected: C
Tested in lab created a ddos plan and the only protected resources I could select are vnet, firewall, application gateway, bastion host, load balancer, NIC, VMSS, and vnet gateway. No option for a webapp directly, Only via the app gateway
egore_E3 👍 2
Why wouldnt it be C then?
pentium75 👍 3 Selected: C
"A DDoS protection plan defines a set of virtual networks that have DDoS Network Protection enabled ... Although DDoS Protection Plan resources needs to be associated with a region, users can enable DDoS protection on Virtual Networks in different regions" https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection (For DDoS protection of a Web App, you need WAF, not a "DDoS Protection Plan".)
Pillartech 👍 1 Selected: E
Answer E: is correct
Jimmy500 👍 4
I think here answer is C as in order to add DDOS protection to Web App we should have application gateway deployed to the vnet but here we can not talk about WAF deployed that is why I would go with C. Enable DDOS Protection Standard on the virtual network hosting your App Service's Web Application Firewall. Azure provides DDoS Basic protection on its network, which can be improved with intelligent DDoS Standard capabilities which learns about normal traffic patterns and can detect unusual behavior. DDoS Standard applies to a Virtual Network so it must be configured for the network resource in front of the app, such as Application Gateway or an NVA. https://learn.microsoft.com/en-us/security/benchmark/azure/baselines/app-service-security-baseline BR
RaphaelG 👍 1 Selected: E
Answer E: as per chiquito explanation
e2b11ca 👍 2 Selected: C
A DDoS protection plan defines a set of virtual networks that have DDoS Network Protection enabled, across subscriptions.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure DDoS Protection Standard is designed to protect infrastructure at the network layer. A DDoS Protection Plan is a container that groups Virtual Networks (VNets) for centralized management. According to Microsoft documentation, you can enable DDoS Network Protection on any VNet in your subscription, regardless of region. Therefore, both VNet1 and VNet2 can be added to the plan.

Why the Other Options Are Wrong

Web App1 is an Azure App Service (PaaS). You cannot directly associate a Web App with a DDoS Protection Plan. To protect a Web App against DDoS attacks, it must be fronted by an Application Gateway with Web Application Firewall (WAF) enabled, which then gets associated with the DDoS Protection Plan. Since the diagram does not show an Application Gateway, WebApp1 is excluded from direct inclusion in the plan.

Community Comment Notes

Several users correctly identified C as the answer, noting that DDoS plans only apply to VNets. One user noted that while Web Apps have basic protection, standard DDoS protection requires an Application Gateway. Another user pointed out that DDoS plans can span regions, confirming VNet1 and VNet2 are valid despite potentially being in different regions. The majority consensus supports C based on technical constraints.

Official Reference

Exam Strategy

Always distinguish between Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) when considering security controls. For DDoS protection, remember that only VNets, Firewalls, and Load Balancers can be directly added to a Protection Plan; App Services require a WAF-enabled Application Gateway.

Frequently Asked Questions

Can I add an Azure Web App directly to a DDoS Protection Plan?

No. Web Apps are PaaS services and do not have their own public IP address managed by the user. They must be protected via an Application Gateway with WAF.

Can a DDoS Protection Plan include VNets from different regions?

Yes. Although the plan itself is created in a specific region, it can protect VNets across multiple regions and subscriptions within the same tenant.

Related Analysis

← Back to AZ-500 Study Guide