The canal authority wants Azure Firewall to drop traffic to or from known malicious IPs and domains, not only log them. Which threat-intelligence mode should the security engineer set?
Select an answer to reveal the explanation.
Short Explanation
Want the firewall to actually drop bad IPs and domains? Choose Alert and deny—not Off, and not Alert-only which just writes a diary entry.
Full Explanation
Azure Firewall threat intelligence can be Off, Alert only, or Alert and deny. Alert and deny both logs and blocks traffic involving known malicious IPs and domains, matching the requirement to drop rather than only observe. Alert only does not enforce deny at the firewall. Sentinel analytics and Defender for Cloud Secure Score are Domain 4 operations/posture tools and do not replace the firewall threat-intelligence mode.