The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
A denial-of-service attack tries to make an application unavailable by exhausting its resources. When many machines attack at once, it is a distributed denial-of-service (DDoS) attack. Any endpoint reachable from the internet can be a target, so Azure includes a basic level of DDoS protection for everyone and sells enhanced tiers.
Learn sorts DDoS attacks into three groups:
| Attack type | What it does | Examples | Mitigated by |
|---|---|---|---|
| Volumetric | Floods the network layer with huge amounts of seemingly legitimate traffic | UDP floods, ICMP floods, reflection amplification | Azure DDoS Protection (absorbs and scrubs the traffic) |
| Protocol | Exploits weaknesses in the layer 3 and layer 4 protocol stack | SYN floods, fragmented packet attacks, ping of death | Azure DDoS Protection |
| Resource (application) layer | Targets web application traffic at layer 7 | HTTP floods, Slowloris, SQL injection, cross-site scripting | A web application firewall (WAF), used alongside DDoS Protection |
Layers 3 and 4 are the network and transport layers (IP addresses, TCP and UDP); layer 7 is the application layer (for example HTTP requests).
Azure DDoS Protection comes in three levels:
| Tier | Cost | What it covers | Extras |
|---|---|---|---|
| DDoS infrastructure protection | Free, always on, no configuration | Every Azure service that uses a public IPv4 or IPv6 address, including PaaS (platform as a service) services | None |
| DDoS Network Protection | Paid plan, priced per 100 protected public IP addresses; one plan can cover virtual networks across subscriptions in a tenant | Resources in the virtual networks linked to the plan, including Basic tier public IPs | DDoS Rapid Response support, cost protection, WAF discount |
| DDoS IP Protection | Paid per protected public IP; no plan needed | Individual public IP resources (not Basic tier public IPs) | None of the extras |
Both paid tiers share the same core engine: always-on traffic monitoring, automatic layer 3/4 mitigation, policies tuned to the application’s own traffic, metrics, alerts, mitigation reports and flow logs, and a Microsoft Sentinel data connector. The differences are the value-added services:
Common trap: Expecting Azure DDoS Protection to stop HTTP floods, SQL injection or cross-site scripting - every tier mitigates layer 3 and 4 attacks only; layer 7 protection needs a web application firewall alongside it.
Common trap: Choosing DDoS IP Protection to get help from Microsoft during an attack - Rapid Response, cost protection and the WAF discount come only with DDoS Network Protection.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.