AZ-700 exam dumps

AZ-700 practice question 279 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 279

Select 2

Your organization has multiple regional environments connected through Azure Virtual WAN. You want to centrally manage and enforce firewall rules for all inbound and outbound traffic in these regions with minimal repetitive configuration. Which two actions should you take to meet these requirements?

  1. A

    Deploy an Azure Firewall in each spoke VNet and manually replicate the rules across each deployment.

  2. B

    Use Azure Firewall Manager to create a Firewall Policy and associate it with a secured virtual hub in each region.

  3. C

    Deploy a secured virtual hub in each region and attach Azure Firewall to each secured hub.

  4. D

    Create multiple custom route tables in each spoke VNet to route traffic selectively to on-premises networks.

  5. E

    Enable default route policies in Azure Firewall Manager to automatically redirect all traffic to on-premises firewalls.

Show answer and explanation

Correct answers: B, C

Explanation

By leveraging Azure Firewall Manager to create a centralized Firewall Policy (Option 2) and deploying Azure Firewall in secured virtual hubs (Option 3), you ensure a single point of management for inbound and outbound rules. This design aligns with best practices for protecting complex Azure environments as documented in the Azure Firewall Manager overview (https://learn.microsoft.com/azure/firewall-manager/overview). Deploying separate firewalls in each spoke VNet or relying purely on route tables introduces significant management overhead and lack of policy consistency.

  • A. Incorrect.

    Option 1 is incorrect. Deploying an Azure Firewall in each spoke VNet creates significant administrative overhead since you have to replicate and update policy changes manually across each firewall. Azure Firewall Manager is designed to avoid this by centralizing policy management.

  • B. Correct.

    Option 2 is correct. Creating a Firewall Policy in Azure Firewall Manager and associating it with each secured virtual hub allows you to manage inbound and outbound rules from a single location, applying changes across all regions without duplicating effort.

  • C. Correct.

    Option 3 is correct. You must deploy a secured virtual hub for each region where you need centralized security. Attaching Azure Firewall to these hubs ensures all traffic from connected spoke VNets flows through a consistent inspection point that enforces the managed policy.

  • D. Incorrect.

    Option 4 is incorrect. While you can define custom route tables, simply creating multiple route tables in each spoke VNet does not provide a centralized policy or simplified deployment. You still need Azure Firewall in a secured hub to enforce security standards effectively.

  • E. Incorrect.

    Option 5 is incorrect. Azure Firewall Manager does not offer a feature that automatically redirects all spoke traffic to on-premises firewalls by default. You must explicitly configure routing and firewall policies, which includes setting up secured hubs and associating the correct Firewall Policy.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam