AZ-700 exam dumps

AZ-700 practice question 293 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 293

Select 2

You have an existing Azure Virtual WAN environment with multiple site-to-site VPN connections from on-premises networks and several connected virtual network (VNet) spokes. You want to secure both inbound and outbound traffic by deploying Azure Firewall inside an Azure Virtual WAN hub. Which two actions must you perform to ensure traffic is properly routed through Azure Firewall?

  1. A

    Enable the Secured Virtual Hub feature within Azure Firewall Manager and associate your hub to the new firewall policy.

  2. B

    Deploy a standalone Azure Firewall instance in each VNet spoke, then configure user-defined routes to forward traffic to every firewall.

  3. C

    Create a custom route table in the virtual hub that sets the Azure Firewall as the default route for 0.0.0.0/0, and associate it with each VNet connection.

  4. D

    Enable on-premises forced tunneling to Azure Firewall by adding the firewall� private IP as the static next hop for your local router.

Show answer and explanation

Correct answers: A, C

Explanation

When creating a secure hub with Azure Firewall in a Virtual WAN environment, you must enable the secured virtual hub feature in Firewall Manager and set up a firewall policy that applies to the hub. Then, you associate a custom route table with all your connected VNets, directing their traffic to the firewall. Following Microsoft� best practices ensures centralized policy management and consistent security across Azure and on-premises networks. For more details, see the Azure Firewall Manager and Virtual WAN documentation in Microsoft Learn.

  • A. Correct.

    Correct. When using Azure Firewall with Virtual WAN, you must enable the Secured Virtual Hub feature via Azure Firewall Manager. This creates and associates a firewall policy to the virtual hub, allowing you to define and enforce security rules for traffic flowing through the hub.

  • B. Incorrect.

    Incorrect. You typically deploy Azure Firewall centrally in the secured virtual hub rather than deploying a separate firewall in each spoke. Spoke VNets simply connect to the hub, which simplifies the management and scaling of firewall services.

  • C. Correct.

    Correct. To ensure traffic from connected VNets is inspected by Azure Firewall, you must create a custom hub route table that sets the next hop to the firewall for the default route (0.0.0.0/0) and associate it with each VNet connection. This ensures traffic is routed to the Azure Firewall in the hub.

  • D. Incorrect.

    Incorrect. While forced tunneling can be used in certain scenarios, simply configuring on-premises routers to point at the firewall� private IP is not sufficient for a fully secure and supported design. You should use the built-in secured virtual hub routing capabilities and firewall policies to manage how on-premises traffic is directed to the firewall.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam