Azure DDoS Protection Plan Resource Eligibility
You have an Azure subscription that contains the resources shown in the following table. You create an Azure DDoS Protection plan named DDoS1 in the West US Azure region. Which resources can you add to DDoS1? - 
Community Votes
85% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of DDoS Protection plan scope; the common trap is assuming PaaS services like Web Apps can be directly protected by a DDoS plan.
Determines which Azure resources can be added to a DDoS Protection plan. The correct answer is C because DDoS Protection plans only support Virtual Networks, not individual PaaS services like Web Apps.
Many candidates choose E (VNet1, VNet2, and WebApp1) because they assume all listed resources are eligible for protection, missing that Web Apps require an Application Gateway with WAF for DDoS protection.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure DDoS Protection Standard is designed to protect infrastructure at the network layer. A DDoS Protection Plan is a container that groups Virtual Networks (VNets) for centralized management. According to Microsoft documentation, you can enable DDoS Network Protection on any VNet in your subscription, regardless of region. Therefore, both VNet1 and VNet2 can be added to the plan.Why the Other Options Are Wrong
Web App1 is an Azure App Service (PaaS). You cannot directly associate a Web App with a DDoS Protection Plan. To protect a Web App against DDoS attacks, it must be fronted by an Application Gateway with Web Application Firewall (WAF) enabled, which then gets associated with the DDoS Protection Plan. Since the diagram does not show an Application Gateway, WebApp1 is excluded from direct inclusion in the plan.Community Comment Notes
Several users correctly identified C as the answer, noting that DDoS plans only apply to VNets. One user noted that while Web Apps have basic protection, standard DDoS protection requires an Application Gateway. Another user pointed out that DDoS plans can span regions, confirming VNet1 and VNet2 are valid despite potentially being in different regions. The majority consensus supports C based on technical constraints.Official Reference
Exam Strategy
Always distinguish between Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) when considering security controls. For DDoS protection, remember that only VNets, Firewalls, and Load Balancers can be directly added to a Protection Plan; App Services require a WAF-enabled Application Gateway.
Frequently Asked Questions
Can I add an Azure Web App directly to a DDoS Protection Plan?
No. Web Apps are PaaS services and do not have their own public IP address managed by the user. They must be protected via an Application Gateway with WAF.
Can a DDoS Protection Plan include VNets from different regions?
Yes. Although the plan itself is created in a specific region, it can protect VNets across multiple regions and subscriptions within the same tenant.