Configure WAF Rate Limiting for Azure Front Door
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Front Door Premium profile named AFD1 and an Azure Web Application Firewall (WAF) policy named WAF1. AFD1 is associated with WAF1. You need to configure a rate limit for incoming requests to AFD1. Solution: You configure a managed rule for WAF1. Does this meet the goal?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Azure WAF rate limits are configured via custom rules, testing the distinction between custom and managed rule capabilities.
Rate limiting in an Azure Web Application Firewall (WAF) policy requires a custom rule, not a managed rule. This page establishes why configuring a managed rule fails to meet the goal of setting a rate limit for Azure Front Door.
Choosing Yes because managed rules are the most common WAF configuration, overlooking that rate limits strictly require custom rules.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is No because rate limiting in an Azure WAF policy is configured by creating a custom rule, not a managed rule. Managed rules consist of pre-defined rule sets designed to protect against common web vulnerabilities, such as those defined by OWASP. They do not offer the specific threshold and time window configurations required for rate limiting. Therefore, configuring a managed rule does not achieve the stated goal.Why the Other Options Are Wrong
Option A (Yes) is incorrect because it assumes managed rules can be used for rate limiting. While managed rule sets are highly effective for signature-based threat detection, they lack the customizable rate limit properties (like request threshold and duration) that custom rules provide. Selecting Yes demonstrates a misunderstanding of WAF rule types and their specific functionalities.Community Comment Notes
The community unanimously agrees that a custom rule is required, as matanzpl noted, "its not a MANAGED rule - its a CUSTOM WAF rule where you configure rate limits". Similarly, bobothewiseman pointed out that you "need to create a custom rule". These comments correctly identify that rate limiting is a feature of custom WAF rules, not managed rule sets.Official Reference
Exam Strategy
Remember that managed WAF rules provide signature-based protection against common vulnerabilities, while custom WAF rules are used for specific logic like rate limiting, IP allow/block lists, and geo-filtering.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →