A canal authority’s production public IPs sit in front of Application Gateway and Azure Firewall, and a past flood exhausted scale-out without anyone being paged. When should the security engineer recommend Azure DDoS Protection Standard?
Select an answer to reveal the explanation.
Short Explanation
Public IPs in front of the locks are what the flood hits—Standard gives you adaptive L3/L4 shields plus Monitor metrics so someone gets paged. No public IP? Don’t buy Standard for that VNet. WAF is the web layer; DDoS Standard is the pipe layer.
Full Explanation
Azure DDoS Protection Standard (Network Protection on a virtual network, or IP Protection on selected public IPs) adds adaptive Layer 3/Layer 4 mitigation, Azure Monitor metrics and alerts, and mitigation logs for internet-facing endpoints such as Application Gateway and Azure Firewall public IPs. Recommend it when public IPs exist and tuned protection plus telemetry are required; do not recommend it for resources with no public IP. Web Application Firewall addresses Layer 7 web attacks and does not replace DDoS Standard for volumetric network floods. Sentinel incident hunting is a separate Domain 4 capability and is not a substitute for enabling DDoS Protection Standard.