Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

Figure 2: Hub-and-Spoke topology with Azure Firewall centralizing inspection
Network Security Group (NSG)
Definition: A software firewall that contains security rules to allow or deny inbound and outbound network traffic to Azure resources.
Day-to-Day Example: Like a building's security checklist at every door, deciding which visitors are let in or turned away.
Application Security Group (ASG)
Definition: A logical grouping of VMs by application role, used inside NSG rules instead of referencing individual IP addresses.
Day-to-Day Example: Like giving all kitchen staff the same colored uniform so a single security rule can apply to everyone wearing it.
Azure Firewall
Definition: A managed, stateful, cloud-based network security service that centrally filters traffic across VNets and subscriptions.
Day-to-Day Example: Like a company's central security checkpoint that every visitor, delivery, and vehicle must pass through, no matter which building they're headed to.
Azure Bastion
Definition: A fully managed service that provides secure RDP/SSH connectivity to VMs through the Azure Portal, without a public IP on the VM.
Day-to-Day Example: Like entering a secure building through a single monitored front desk instead of climbing in through individual windows.
Just-in-Time (JIT) VM Access
Definition: A feature that locks down inbound management ports and opens them only for a limited time after an approved request.
Day-to-Day Example: Like a vault door that only unlocks for a pre-approved 15-minute window instead of staying open all day.
Service Endpoint
Definition: A feature that routes traffic from a VNet to a PaaS service over the Azure backbone while the service keeps a public endpoint.
Day-to-Day Example: Like taking a company's private shuttle to a partner office, even though that office still has a public front door.
Private Endpoint
Definition: A network interface that uses a private IP address from your VNet to connect privately to a PaaS service.
Day-to-Day Example: Like giving a supplier their own private entrance directly into your building, with no need to use the public street.
Private Link
Definition: The Azure technology that powers Private Endpoints, enabling private connectivity to PaaS and partner services over the Microsoft backbone.
Day-to-Day Example: Like the private courier network that makes direct, sealed deliveries possible between two specific buildings.
User-Defined Route (UDR)
Definition: A custom route that overrides Azure's default system routing to send traffic through a specific next hop, such as a firewall.
Day-to-Day Example: Like a manager instructing all deliveries to go through the loading dock instead of the default front entrance.
VNet Peering
Definition: A connection linking two Virtual Networks so their resources communicate using private IP addresses over the Microsoft backbone.
Day-to-Day Example: Like building a private hallway directly between two office buildings so staff never have to step outside.
DDoS Protection Standard
Definition: A paid tier of Azure's DDoS mitigation service offering enhanced detection, mitigation, and cost protection during an attack.
Day-to-Day Example: Like upgrading from a basic door lock to a monitored security team that actively responds when a mob tries to force its way in.
Web Application Firewall (WAF)
Definition: A security service that filters and monitors HTTP traffic to protect web applications from common exploits like SQL injection and XSS.
Day-to-Day Example: Like a bouncer who inspects every visitor's bag before letting them into a public event, not just checking their ticket.
Azure Front Door
Definition: A global, scalable entry point providing load balancing, WAF, and acceleration for web applications across Azure regions.
Day-to-Day Example: Like an airport's central arrivals hall that routes every traveler to the fastest, nearest available gate.
VPN Gateway
Definition: An Azure resource that creates an encrypted Site-to-Site or Point-to-Site tunnel between on-premises networks and Azure over the internet.
Day-to-Day Example: Like sending sensitive documents through a locked courier bag over regular public roads.
ExpressRoute
Definition: A private, dedicated connection from on-premises infrastructure to Azure that bypasses the public internet entirely.
Day-to-Day Example: Like having a private dedicated highway lane straight to headquarters instead of driving on public roads.
Network Watcher
Definition: A monitoring and diagnostics service that provides tools to view, diagnose, and gain insights into Azure network performance and health.
Day-to-Day Example: Like a building's CCTV and access-log system that lets security review exactly who went where and when.
NAT Gateway
Definition: A managed service that provides scalable, secure outbound-only internet connectivity for resources within a subnet.
Day-to-Day Example: Like a single shared mailroom that sends outgoing company mail without ever revealing each employee's personal address.
Load Balancer
Definition: A Layer 4 (TCP/UDP) service that distributes inbound network traffic across multiple healthy backend VMs.
Day-to-Day Example: Like a receptionist directing incoming visitors evenly across several available service counters.
Application Gateway
Definition: A Layer 7 (HTTP/HTTPS) load balancer that also provides URL-based routing, SSL termination, and integrated WAF capability.
Day-to-Day Example: Like a smart concierge who reads each visitor's request and sends them to the exact right department, not just the nearest one.
Network Security Perimeter
Definition: A boundary concept that groups multiple PaaS resources so a single set of network access rules governs all of them together.
Day-to-Day Example: Like fencing an entire campus of buildings with one shared gate policy instead of a separate gate for every building.

Figure 3: Site-to-Site VPN Gateway vs. ExpressRoute connectivity paths
1. NSG vs. Application Security Group (ASG)
Feature Network Security Group (NSG) Application Security Group (ASG) Purpose Filters inbound/outbound traffic with allow/deny rules Groups VMs by application role for use inside NSG rules Applies to Subnets and network interfaces Network interfaces of grouped VMs Example "Deny all inbound except port 443" "WebServers" group referenced inside an NSG rule
2. NSG vs. Azure Firewall
Feature NSG Azure Firewall Scope Subnet or NIC level, within one VNet Centralized, across multiple VNets/subscriptions Rule type Basic allow/deny by IP, port, protocol Application (FQDN), network, and NAT rules Best for Simple, local traffic filtering Centralized, enterprise-wide traffic control
3. Service Endpoint vs. Private Endpoint
Feature Service Endpoint Private Endpoint Public exposure PaaS service keeps a public endpoint PaaS service gets a private IP, no public exposure Traffic path Stays on Azure backbone from the VNet Fully private, direct connection via Private Link Cross-region/VNet access Limited to the same region/VNet setup Works across VNets, regions, and even on-premises
4. VPN Gateway vs. ExpressRoute
Feature VPN Gateway ExpressRoute Connection path Over the public internet, encrypted Private, dedicated circuit, not over the internet Reliability/latency Depends on internet conditions Consistent, low-latency, high reliability Typical use Smaller organizations, backup connectivity Large enterprises needing guaranteed performance
5. Load Balancer vs. Application Gateway
Feature Load Balancer Application Gateway OSI Layer Layer 4 (TCP/UDP) Layer 7 (HTTP/HTTPS) Routing logic Distributes by IP/port only URL-based, host-based routing with SSL termination Extra features None beyond basic distribution Integrated Web Application Firewall (WAF)
6. DDoS Protection Basic vs. Standard
Feature DDoS Basic DDoS Standard Cost Free, automatically enabled Paid, must be explicitly enabled Mitigation Always-on, platform-level protection Enhanced, tuned mitigation with alerting Extras None Attack analytics, metrics, and cost protection
7. VNet Peering vs. VPN Gateway (VNet-to-VNet)
Feature VNet Peering VPN Gateway (VNet-to-VNet) Traffic path Microsoft backbone network Encrypted tunnel, can traverse the internet Performance Low latency, high bandwidth Lower throughput, encryption overhead Best for VNets needing fast, direct connectivity Scenarios requiring encrypted connectivity or overlapping setups
8. Azure Bastion vs. Traditional Jump Box
Feature Azure Bastion Traditional Jump Box Public IP needed on target VM No Yes, or a separate jump VM with a public IP Management overhead Fully managed by Azure Customer manages patching, scaling, security Access method Browser-based, through the Azure Portal Dedicated RDP/SSH client to a jump VM
9. Web Application Firewall (WAF) vs. Azure Firewall
Feature WAF Azure Firewall Protocol focus HTTP/HTTPS (Layer 7) web traffic All protocols (Layers 3–7), broader network traffic Protects against SQL injection, XSS, common web exploits Unauthorized network/application access generally Deployed with Application Gateway or Front Door Standalone, in a hub VNet
10. NAT Gateway vs. Load Balancer Outbound Rules
Feature NAT Gateway Load Balancer Outbound Rules Purpose Dedicated, scalable outbound-only connectivity Outbound connectivity as a side effect of inbound LB rules SNAT port exhaustion Much less likely, higher port allocation More likely under heavy outbound load Setup complexity Simple, attach to a subnet Requires configuring backend pool and rules

Figure 4: Public endpoint vs. Private Endpoint access to an Azure PaaS service
4. Theoretical Questions (15)
Q1. What is a Network Security Group (NSG), and what does it control?
Answer: An NSG is a firewall-like resource containing rules that allow or deny inbound and outbound traffic to Azure resources such as VMs and subnets, controlling what network traffic is permitted.
Q2. How are NSG rules evaluated when multiple rules could apply?
Answer: NSG rules are evaluated in order of priority number, from lowest to highest; the first matching rule is applied and evaluation stops, so lower numbers take precedence.
Q3. What is an Application Security Group (ASG), and why is it useful?
Answer: An ASG groups VMs by application role so NSG rules can reference the group by name instead of listing individual IP addresses, simplifying rule management as VMs are added or removed.
Q4. What is Azure Firewall, and how does it differ from an NSG?
Answer: Azure Firewall is a centralized, managed firewall-as-a-service that filters traffic across multiple VNets and subscriptions using application, network, and NAT rules, while an NSG only filters traffic at a subnet or NIC level within one VNet.
Q5. What is a Hub-and-Spoke topology, and why is it used for network security?
Answer: A Hub-and-Spoke topology places shared services like Azure Firewall in a central Hub VNet, with Spoke VNets routing their traffic through it, so all traffic can be inspected and controlled from one place.
Q6. What is Azure Bastion, and what problem does it solve?
Answer: Azure Bastion provides secure RDP/SSH access to VMs through the Azure Portal over TLS, solving the problem of needing to expose a VM's public IP just to manage it remotely.
Q7. What is Just-in-Time (JIT) VM Access, and how does it reduce risk?
Answer: JIT VM Access keeps management ports closed by default and opens them only for a limited time after an approved request, reducing the window during which attackers could target those ports.
Q8. What is the difference between a Service Endpoint and a Private Endpoint?
Answer: A Service Endpoint routes VNet traffic to a PaaS service over the Azure backbone while the service keeps a public endpoint, whereas a Private Endpoint assigns the PaaS service a private IP inside the VNet, removing public exposure entirely.
Q9. What is a User-Defined Route (UDR), and when would an administrator create one?
Answer: A UDR overrides Azure's default system routes to send traffic through a specific next hop, such as a firewall appliance; administrators create one when they need traffic to be inspected or redirected instead of taking the default path.
Q10. What is VNet Peering, and why is it described as non-transitive?
Answer: VNet Peering connects two VNets so resources communicate using private IPs over the Microsoft backbone; it is non-transitive because peering between A–B and B–C does not automatically let A reach C through B.
Q11. What are the two tiers of Azure DDoS Protection, and how do they differ?
Answer: The two tiers are Basic, which is free and automatically enabled with platform-level protection, and Standard, a paid tier with enhanced mitigation, attack analytics, alerting, and cost protection.
Q12. What is a Web Application Firewall (WAF), and what does it protect against?
Answer: A WAF filters and monitors HTTP/HTTPS traffic to protect web applications from common exploits like SQL injection and cross-site scripting (XSS), and is typically deployed with Application Gateway or Front Door.
Q13. What is the difference between VPN Gateway and ExpressRoute?
Answer: VPN Gateway creates an encrypted tunnel between on-premises networks and Azure over the public internet, while ExpressRoute provides a private, dedicated circuit that bypasses the public internet for more consistent performance.
Q14. What does Network Watcher provide, and why is it useful?
Answer: Network Watcher provides monitoring and diagnostic tools, such as NSG flow logs and IP flow verify, letting administrators visualize and troubleshoot network health and security rule behavior.
Q15. What is a NAT Gateway, and what problem does it solve for outbound connectivity?
Answer: A NAT Gateway provides scalable, managed outbound-only internet connectivity for resources in a subnet, solving SNAT port exhaustion issues without needing a public IP on every VM.
5. Scenario-Based Questions (8)
Q1. A company wants VMs in a subnet to communicate freely with each other but block all inbound traffic from the internet except HTTPS. What should they configure?
Answer: They should configure an NSG on the subnet with a rule allowing inbound traffic on port 443 (HTTPS) and rely on the default rules to allow VNet-to-VNet traffic while denying other inbound internet traffic.
Q2. An administrator manages 30 web server VMs and needs to apply the same NSG rule to all of them without listing 30 IP addresses. What should they use?
Answer: They should create an Application Security Group (ASG) containing all 30 web server VMs and reference the ASG in a single NSG rule, so the rule automatically applies to every member.
Q3. A company with multiple VNets across departments wants all traffic between them and to the internet inspected by one central security appliance. What architecture fits?
Answer: A Hub-and-Spoke topology with Azure Firewall deployed in the Hub VNet fits best, since all Spoke VNets can route their traffic through the hub for centralized inspection.
Q4. An admin needs to RDP into a VM occasionally but does not want to assign it a public IP or leave port 3389 open. What Azure feature should they use?
Answer: They should use Azure Bastion (optionally combined with Just-in-Time VM Access) to connect securely through the Azure Portal without exposing a public IP or leaving the RDP port open.
Q5. A company wants its Azure SQL Database to be reachable only from within its VNet, with no public internet exposure at all. What should they configure?
Answer: They should configure a Private Endpoint for the Azure SQL Database, giving it a private IP address inside the VNet and removing its public endpoint exposure.
Q6. An organization needs guaranteed low-latency, high-reliability connectivity between its on-premises datacenter and Azure for a critical workload. What should they choose?
Answer: They should choose ExpressRoute, since it provides a private, dedicated circuit that bypasses the public internet, offering more consistent latency and reliability than a VPN Gateway.
Q7. A web application is being hit with SQL injection attempts. What Azure service should be added in front of it?
Answer: A Web Application Firewall (WAF), deployed with Application Gateway or Azure Front Door, should be added in front of the application to detect and block SQL injection and similar exploits.
Q8. A subnet full of backend VMs needs outbound internet access for updates, but the team is hitting SNAT port exhaustion with their current Load Balancer setup. What should they deploy?
Answer: They should deploy a NAT Gateway on the subnet, which provides scalable, dedicated outbound-only connectivity with a much higher SNAT port allocation than relying on Load Balancer outbound rules.