AZ-700 exam dumps

AZ-700 practice question 287 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 287

Select 2

Your company has deployed a hub-and-spoke network topology in Azure. The hub virtual network contains an Azure Firewall in a dedicated subnet named 'AzureFirewallSubnet.' You need to route all outbound traffic from virtual machines in the spoke subnets through Azure Firewall for inspection. Which two configuration steps must you perform to meet this requirement?

  1. A

    Create a user-defined route (UDR) in each spoke subnet that sets the next hop to the Azure Firewall� private IP address.

  2. B

    Deploy an additional network security group (NSG) in the same subnet as the Azure Firewall to manage routing.

  3. C

    Configure a firewall policy or rule collection on the Azure Firewall to allow outbound traffic on required ports.

  4. D

    Place the Azure Firewall in each spoke subnet to filter traffic at the local subnet level.

  5. E

    Associate the default route table with the hub VNet gateway subnet only.

Show answer and explanation

Correct answers: A, C

Explanation

To inspect outbound traffic via Azure Firewall, organizations typically deploy the firewall in a dedicated AzureFirewallSubnet in the hub virtual network. They then create user-defined routes on the spoke subnets directing traffic to the firewall� private IP address. Additionally, appropriate firewall rules or policies must be configured to allow or block desired outbound traffic. Microsoft� documentation recommends this hub-and-spoke architecture for central management and inspection of network traffic (see 'Tutorial: Deploy and configure Azure Firewall using the Azure portal' and 'Hub-spoke network topology in Azure').

  • A. Correct.

    Correct. You must create a user-defined route in each spoke subnet specifying the Azure Firewall� private IP as the default route (0.0.0.0/0). This ensures all outbound traffic from VMs in the spokes is directed to the firewall.

  • B. Incorrect.

    Incorrect. NSGs primarily control traffic at the subnet or NIC level based on rules but do not provide the required routing changes. You still need the UDR to force outbound traffic to go through the Azure Firewall.

  • C. Correct.

    Correct. By configuring an Azure Firewall policy (or rule collection within the classic model), you can allow or deny outbound traffic on specific ports or protocols, ensuring that legitimate traffic is permitted and inspected.

  • D. Incorrect.

    Incorrect. Azure Firewall must reside in a dedicated subnet named AzureFirewallSubnet within the hub virtual network. Placing the firewall in every spoke subnet is not required and is not considered a best practice.

  • E. Incorrect.

    Incorrect. Simply associating a route table with the hub VNet gateway subnet doesn't route spoke VM traffic through the firewall. You need to associate user-defined routes with each spoke subnet to properly direct traffic.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam