AZ-500 exam dumps

AZ-500 practice question 50 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 50

Single answer

Your organization has multiple Azure Virtual Networks deployed across development, testing, and production subscriptions. You create a single connectivity configuration in Azure Virtual Network Manager (AVNM) to automatically peer these networks in a hub-and-spoke topology. After assigning the hub network, you notice that several virtual networks remain unpeered. You confirm that your connectivity configuration is valid and that the necessary roles are granted. What is the most likely cause of the unpeered virtual networks?

  1. A

    They reside in an unsupported Azure region for AVNM deployments.

  2. B

    They are not associated with the correct network group defined in AVNM.

  3. C

    They do not have a dedicated Azure Firewall resource in each spoke network.

  4. D

    They were created using Resource Manager templates rather than the Portal.

Show answer and explanation

Correct answer: B

Explanation

When using Azure Virtual Network Manager for centrally managed connectivity, you must define network groups containing the specific virtual networks you want to peer or secure. If a virtual network is not assigned to the correct network group that is tied to the connectivity configuration, it will remain unpeered. Refer to the official Azure Virtual Network Manager documentation (docs.microsoft.com/azure/virtual-network-manager) for best practices on assigning networks to groups and creating connectivity configurations.

  • A. Incorrect.

    Incorrect. Azure Virtual Network Manager supports multiple regions, and region incompatibility is not the usual reason for networks failing to peer. Documentation does not list common region restrictions for basic peering.

  • B. Correct.

    Correct. For AVNM to apply connectivity rules automatically, each virtual network must belong to the correct network group in your AVNM configuration. If a network is not included in the same network group as the connectivity configuration, the automatic peering does not occur.

  • C. Incorrect.

    Incorrect. A dedicated Azure Firewall resource in each spoke is not required for hub-and-spoke topology. You can use a single firewall in the hub network, and routing traffic through it can be centrally managed.

  • D. Incorrect.

    Incorrect. How a network is created (Resource Manager template vs. Portal) does not affect AVNM’s ability to peer networks. AVNM only requires that the network is correctly assigned to the configured network group.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam