Which Azure Firewall Rule Type Filters by FQDN?
You have an Azure subscription that contains the resources shown in the following table. You need to configure FW1 to filter traffic that originates from VNet1 and targets the FQDN of SQLDB1. Which type of rule should you use? - 
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Azure Firewall application rules enable FQDN-based filtering, whereas network rules only support IP address-based filtering.
Azure Firewall uses application rules to filter outbound traffic based on Fully Qualified Domain Names (FQDNs). This page establishes why application rules are required over network rules when targeting an FQDN like an Azure SQL Database.
Choosing network rules (B) because they are commonly used for VNet traffic, but they cannot target FQDNs.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Application rules in Azure Firewall are specifically designed to allow or deny traffic based on Fully Qualified Domain Names (FQDNs). When the requirement specifies targeting the FQDN of SQLDB1, an application rule is the necessary configuration. This rule type processes traffic and can resolve the FQDN to its underlying IP addresses dynamically to enforce filtering.Why the Other Options Are Wrong
DNAT rules are used for destination network address translation, primarily to expose internal services to external traffic, not for outbound FQDN filtering. Network rules filter traffic based strictly on source and destination IP addresses, ports, and protocols, lacking the ability to resolve or target FQDNs. Infrastructure is not a valid rule type within Azure Firewall policy rule sets.Community Comment Notes
Commenters emphasized that application rules allow outbound filtering based on FQDNs, directly addressing the requirement for SQLDB1. One user noted that network rules only support IP addresses and cannot be used for FQDN targets. Another pointed out that DNAT is for inbound translation, reinforcing why application rules are the correct choice.Official Reference
Exam Strategy
When an Azure Firewall question specifies filtering by FQDN, immediately look for the application rule option. Reserve network rules for IP and port-based filtering, and DNAT for inbound port forwarding.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →