AZ-500 exam dumps

AZ-500 practice question 58 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 58

Single answer

Your company has deployed a global Azure Virtual WAN with multiple branch offices connected to a secured virtual hub. You want to ensure that all Internet-bound traffic from one specific branch office is inspected by the Azure Firewall in the secured virtual hub. Which of the following actions is required to achieve this?

  1. A

    Create a custom route table in the secured virtual hub with a default route (0.0.0.0/0) that points to the Azure Firewall as the next hop.

  2. B

    Enable the built-in 'Any-to-Any' routing feature in Virtual WAN so that all branch traffic automatically flows through the firewall.

  3. C

    Set the default route propagation in the secured hub’s default route table to include the 0.0.0.0/0 prefix.

  4. D

    Configure a user-defined route in each branch VNet that points the next hop to the branch’s on-premises router for further inspection.

Show answer and explanation

Correct answer: A

Explanation

When using a secured virtual hub in Azure Virtual WAN, you must configure routes so that traffic intended for the Internet or other networks flows through Azure Firewall for inspection. By creating a custom route table with a 0.0.0.0/0 route pointing to the firewall, you ensure that all outbound traffic is inspected. Microsoft documentation recommends establishing a custom route table that forces tunneling of all traffic through Azure Firewall. For reference, see Azure Virtual WAN documentation: https://learn.microsoft.com/azure/virtual-wan/virtual-wan-about.

  • A. Correct.

    Correct. To force all Internet-bound traffic through Azure Firewall in the secured virtual hub, you must configure a custom route table and specify 0.0.0.0/0 with the Azure Firewall as the next hop. This ensures that the hub redirects outbound traffic to the firewall for inspection.

  • B. Incorrect.

    Incorrect. While Virtual WAN can enable connectivity, simply enabling 'Any-to-Any' routing does not guarantee traffic inspection. You must explicitly direct traffic to the Azure Firewall via routing rules.

  • C. Incorrect.

    Incorrect. Propagating prefixes in the default route table will not automatically force traffic through the firewall. A custom route table with a default route directing traffic to the Azure Firewall is necessary for inspection.

  • D. Incorrect.

    Incorrect. Configuring user-defined routes in the branch VNet that point to the on-prem router would bypass Azure Firewall in the secured virtual hub. The routing needs to be set at the hub to send traffic to the firewall for inspection, not back to on-prem.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam