AZ-700 exam dumps

AZ-700 practice question 54 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 54

Single answer

You manage an Azure environment that is connected to your on-premises network via a site-to-site VPN. The security team requires all outbound traffic from virtual machines in a specific Azure subnet to first flow through an on-premises firewall for inspection. How should you configure forced tunneling to meet this requirement?

  1. A

    Create a user-defined route (UDR) with a default route (0.0.0.0/0) pointing to the Virtual Network Gateway as the next hop and apply this route table to the specified subnet

  2. B

    Enable forced tunneling by selecting the �Enforce On-Prem Tunnel� checkbox under the Azure virtual network properties

  3. C

    Deploy an additional Azure Firewall in the same subnet and rely on automatic routing to send inbound and outbound traffic through the firewall

  4. D

    Add a UDR with a default route (0.0.0.0/0) to the public Internet IP address of the on-premises firewall and associate it with your GatewaySubnet

Show answer and explanation

Correct answer: A

Explanation

In Azure, forced tunneling is typically implemented by creating a custom route table with a default route pointing to the Virtual Network Gateway as the next hop. This ensures all internet-bound traffic is sent to on-premises for inspection. There is no single option in Azure to 'enable forced tunneling'�rather, you must configure user-defined routes correctly. For more details, see Microsoft documentation at https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm.

  • A. Correct.

    Correct: To force all outbound traffic through the on-premises network, you must create a default route (0.0.0.0/0) in a route table with the Virtual Network Gateway set as the next hop. Associate this route table with the specific subnet to ensure traffic is routed to the VPN gateway and then to on-premises.

  • B. Incorrect.

    Incorrect: There is no �Enforce On-Prem Tunnel� checkbox or a similar direct toggle in Azure virtual network settings. Forced tunneling must be configured via a custom route table and next hop settings.

  • C. Incorrect.

    Incorrect: Simply deploying an Azure Firewall does not automatically force traffic to on-premises. If you wanted to use Azure Firewall as a next hop, you would still have to configure UDRs accordingly, and in this scenario, the requirement is to route traffic on-prem, not through Azure Firewall.

  • D. Incorrect.

    Incorrect: Pointing the route to the on-premises firewall� public IP directly as next hop is not supported. The valid next hop type for forced tunneling to on-premises is the Virtual Network Gateway, which then routes traffic to the on-premises network.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam