A reviewer says Azure already includes DDoS protection so nothing more is needed for a public Application Gateway and a public Azure Firewall. What distinction should the security engineer make?
Select an answer to reveal the explanation.
Short Explanation
Basic platform DDoS is the free umbrella—coarse and quiet. DDoS Protection Standard is what you buy when those public IPs need adaptive tuning, metrics, alerts, and real mitigation reports.
Full Explanation
Azure includes baseline platform/infrastructure DDoS protection for the network, but it is coarse and lacks the per-resource telemetry of the paid plan. Azure DDoS Protection Standard (exam wording; product docs may also say Network Protection / IP Protection) is recommended when internet-facing public IPs require adaptive tuning, metrics, alerts, and mitigation reports. Treating platform protection as identical to Standard under-scopes important public edges. WAF addresses application-layer attacks and does not fully replace network DDoS Protection Standard. Removing public IPs may be valid elsewhere but does not answer when to recommend Standard for public Application Gateway and Firewall IPs you retain.