Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is deploying a mission-critical financial application on Azure Virtual Machines that processes confidential client records. The security team wants to adopt a defense-in-depth security approach to protect the workload and ensure that a single point of failure cannot compromise the entire environment.
Which approach best demonstrates applying a defense-in-depth strategy across multiple security layers in Azure?
Relying exclusively on IP-based access control lists on the public load balancer without requiring identity authentication or transport encryption
Hosting all web, application, and database tiers on a single virtual machine to centralize all security configurations in one location
Combining Network Security Groups for traffic filtering, role-based access control with authentication for identity security, and encryption for data at rest and in transit
Disabling automated key rotation and backups in Azure Key Vault so that encryption keys and database secrets remain static
Relying exclusively on IP-based access control lists on the public load balancer without requiring identity authentication or transport encryption
Hosting all web, application, and database tiers on a single virtual machine to centralize all security configurations in one location
Combining Network Security Groups for traffic filtering, role-based access control with authentication for identity security, and encryption for data at rest and in transit
Defense in depth is a fundamental security architecture strategy that manages organizational risk by deploying multiple independent, diverse defensive mechanisms across several layers. Rather than relying on a single security perimeter, defense in depth creates layered barriers around critical assets—including physical security, identity and access, network perimeters, compute infrastructure, applications, and core data. If any single layer is bypassed or compromised, subsequent layers prevent unauthorized access and minimize overall blast radius.
This approach aligns directly with defense-in-depth principles by establishing independent security controls across critical architectural tiers:
Layering network filtering, identity governance, and cryptographic controls ensures that security is holistic. It protects the financial application across the compute, network, identity, and data layers, delivering complete compliance with Azure best practices.
Disabling automated key rotation and backups in Azure Key Vault so that encryption keys and database secrets remain static