2Secure Networking
- 2.1Traffic Control with NSGs and ASGs
Understand network security groups (NSGs) that allow/deny traffic at subnet/NIC level, and application security groups (ASGs) that group VMs by app role. The basis for minimizing traffic within a virtual network.
- 2.2Azure Firewall and Secure Management Access
Understand Azure Firewall for centralized VNet traffic control, Azure Bastion for secure VM access without public IPs, and NAT gateway to consolidate outbound to one IP—the basics of perimeter defense and secure operational access.
- 2.3Protecting Public Apps with WAF and DDoS
Understand Web Application Firewall (WAF) and DDoS Protection for public apps, plus private endpoints that keep service connectivity inside the VNet. These defend against L7 attacks and volumetric attacks.

