A subnet is associated with a NAT gateway, but outbound traffic from the VMs still leaves through a network virtual appliance because the subnet has a user-defined route for 0.0.0.0/0 with next hop type Virtual appliance. The workload must use the NAT gateway for internet-bound traffic while keeping more specific routes intact. What should the administrator change?
A default UDR to a virtual appliance overrides the system default route, so the NAT gateway never becomes the effective internet egress path. Removing that default route restores normal outbound routing, and the NAT gateway can then provide the public source IP for internet-bound traffic. More specific UDRs for private prefixes can remain in place.
Why this answer
The NAT gateway is designed to provide outbound connectivity for VMs in the subnet, but a user-defined route (UDR) for 0.0.0.0/0 with next hop type Virtual appliance overrides the default route to the NAT gateway. By removing that UDR, the subnet's default route reverts to the system route, which directs internet-bound traffic to the NAT gateway's public IP. More specific routes (e.g., to on-premises networks) remain intact because they are not affected by the removal of the 0.0.0.0/0 route.
Exam trap
The trap here is that candidates often think a NAT gateway requires a UDR to function, when in fact the NAT gateway works via the system default route and a UDR for 0.0.0.0/0 with a different next hop type will override it, breaking the NAT gateway's intended behavior.
Why the other options are wrong
Disabling the network security group does not affect routing; the NAT gateway is bypassed because the 0.0.0.0/0 UDR with next hop Virtual Appliance overrides the default route to the NAT gateway. NSGs control traffic filtering, not routing.
Enabling gateway route propagation adds routes from a VPN gateway or ExpressRoute to the route table, but it does not override the existing 0.0.0.0/0 UDR. The NAT gateway still cannot take effect because the UDR with next hop Virtual appliance remains the preferred route for internet-bound traffic.
Attaching a public IP to each VM NIC would bypass the NAT gateway and the network virtual appliance, but the requirement is to use the NAT gateway for internet-bound traffic while keeping more specific routes intact. This option does not address the conflicting 0.0.0.0/0 route that directs traffic to the virtual appliance.
When would these options actually be correct?
If a subnet's NSG is blocking outbound traffic that should be allowed through a NAT gateway, and the routing is correctly configured to use the NAT gateway, then disabling or modifying the NSG rules could resolve connectivity issues.
In a scenario where a subnet needs to learn on-premises routes via a VPN gateway or ExpressRoute, and the route table does not have a conflicting 0.0.0.0/0 UDR, enabling gateway route propagation would allow those routes to be added automatically.
In a scenario where a VM needs direct outbound internet access without going through a NAT gateway or virtual appliance, and the subnet has no conflicting routes, attaching a public IP to the NIC would be correct. For example, if the requirement is to allow a specific VM to have its own public IP for inbound connections while other VMs use a NAT gateway.
Why candidates pick the wrong answer
Candidates may confuse the roles of NSGs and route tables, thinking that NSGs can override routing decisions or that disabling security will force traffic through the NAT gateway.
Candidates may think that enabling route propagation will allow the NAT gateway's default route to be learned or that it will override the UDR, misunderstanding that gateway propagation only adds routes from a gateway and does not remove existing UDRs.