AZ-500 exam dumps

AZ-500 practice question 59 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 59

Single answer

You administer a global Azure Virtual WAN with multiple branch offices connecting via site-to-site VPN. You have deployed a secured virtual hub that includes Azure Firewall to inspect all traffic passing through Azure. You need to ensure that all branch-to-branch traffic is inspected by the Azure Firewall before reaching its destination. Which configuration step should you implement?

  1. A

    Option 1: Enable BGP propagation to the default route table for the secured hub only.

  2. B

    Option 2: Create a custom route table in the secured virtual hub, specify Azure Firewall as the next hop for 0.0.0.0/0, and associate this route table with the site-to-site VPN connections.

  3. C

    Option 3: Configure each on-premises VPN device to use direct BGP peering with every other branch office.

  4. D

    Option 4: Deploy a network virtual appliance (NVA) in each spoke virtual network to forward traffic to the Azure Firewall.

Show answer and explanation

Correct answer: B

Explanation

When using a secured virtual hub with Azure Firewall in an Azure Virtual WAN, you must create and associate a route table that directs traffic to Azure Firewall as the default next hop. This approach ensures that all traffic, including branch-to-branch, is inspected by Azure Firewall for consistent security enforcement. Refer to official Azure documentation for details: https://learn.microsoft.com/azure/virtual-wan/virtual-wan-route-table.

  • A. Incorrect.

    Explanation for Option 1: Enabling BGP propagation to the default table alone does not automatically force all branch traffic through Azure Firewall. BGP alone will not define a default route that points to the firewall for inspection.

  • B. Correct.

    Explanation for Option 2: Creating a custom route table in the secured hub and associating it with the VPN connections ensures all traffic (including branch-to-branch) moves through Azure Firewall for inspection. This is the correct approach to centrally enforce security policies in a Virtual WAN scenario.

  • C. Incorrect.

    Explanation for Option 3: If each branch office routes directly to other branch offices, traffic bypasses the secured hub and thus bypasses Azure Firewall inspection entirely. This does not meet the requirement for firewall inspection.

  • D. Incorrect.

    Explanation for Option 4: Deploying a dedicated NVA in each spoke is not required when using Azure Firewall in a secured virtual hub. This approach is more complex to manage and not the recommended method for branch-to-branch traffic inspection in Virtual WAN.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam