Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

6.4. Reflection Checkpoint

Key Takeaways

Before proceeding, ensure you can:

  • Configure NSG rules with appropriate priority and service tags
  • Use ASGs to simplify rule management
  • Design hub-spoke architectures with Azure Firewall
  • Choose appropriate Azure Firewall SKU for requirements
  • Deploy and configure WAF on Application Gateway or Front Door

Self-Check Questions

  1. A VM with both subnet NSG and NIC NSG can reach the internet, but traffic to port 443 on another VM in the same VNet is blocked. Where would you look first?

  2. When would you choose Azure Firewall Premium over Standard?

  3. After enabling WAF in Prevention mode, legitimate users are being blocked. What's your troubleshooting approach?

Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications