問題文
In Azure Firewall, in which order are DNAT rules, network rules, and application rules processed, and what happens to application rules if a network rule matches?
選択肢
- The order is configurable per firewall policy.
- Network rules first, then DNAT rules, then application rules; a network rule match still allows the application rules to be evaluated afterward.
- Application rules first, then network rules, then DNAT rules; all rule types are always evaluated.
- DNAT rules first, then network rules, then application rules; if a network rule matches, application rules are not evaluated.