AZ-700 exam dumps

AZ-700 practice question 286 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 286

Select 3

You are designing a hub-and-spoke network in Azure, where a central hub virtual network (VNet) will host an Azure Firewall to inspect and filter outbound traffic from multiple spoke VNets. Which three steps must you take to ensure all outbound traffic from the spokes is inspected by Azure Firewall in the hub?

  1. A

    Deploy Azure Firewall in a dedicated subnet named 'AzureFirewallSubnet' within the hub VNet.

  2. B

    Use a user-defined route table in each spoke subnet to direct 0.0.0.0/0 to the Azure Firewall� private IP address.

  3. C

    Enable 'Use Remote Gateways' on the spoke-to-hub VNet peering from the spokes side.

  4. D

    Configure forced tunneling on Azure Firewall to forward all traffic to an on-premises device through a VPN gateway.

  5. E

    Attach the same user-defined route table to the AzureFirewallSubnet to route firewall-bound traffic back to itself.

Show answer and explanation

Correct answers: A, B, C

Explanation

When designing an Azure Firewall deployment in a hub-and-spoke model, Azure Firewall must be placed in a dedicated AzureFirewallSubnet in the hub VNet. Each spoke subnet should have a custom route table (UDR) directing 0.0.0.0/0 to the firewall's private IP to ensure all outbound traffic is inspected. Additionally, for traffic to traverse from spoke to hub, you must enable the 'Use Remote Gateways' setting in the spokes� peering configuration so that traffic can route to the firewall in the hub. More details can be found in Microsoft documentation under 'Tutorial: Deploy and configure Azure Firewall in a hybrid network.'

  • A. Correct.

    Correct. Azure Firewall must reside in a dedicated subnet named AzureFirewallSubnet. This is a requirement for Azure Firewall deployments.

  • B. Correct.

    Correct. You need user-defined routes that direct 0.0.0.0/0 to the firewall� private IP in order for outbound traffic from the spokes to be inspected by the firewall.

  • C. Correct.

    Correct. To allow the spoke VNets to route outbound traffic through the firewall in the hub VNet, you must enable Use Remote Gateways on the spoke side of the peering.

  • D. Incorrect.

    Incorrect. Forced tunneling to an on-premises device is an additional design option for inspection or compliance requirements, but it is not required to filter outbound traffic with the Azure Firewall in the hub.

  • E. Incorrect.

    Incorrect. Attaching a UDR to the firewall� own subnet can create routing loops. Standard best practices do not recommend associating a UDR with the AzureFirewallSubnet aimed at the firewall itself.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam