Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company uses Azure Firewall to secure outbound traffic from a hub virtual network. The security team reports that some traffic is bypassing the firewall because of asymmetric routing. You need to design a solution to force all outbound traffic through the firewall. What should you implement?

⚠ Common exam trap

Many candidates confuse Azure Firewall Manager's policy enforcement with actual traffic routing, but Firewall Manager does not create UDRs; it only manages firewall policies, and UDRs are still required to direct traffic to the firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall

User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall as the next hop are the correct solution because they override the system default route and force all outbound traffic from subnets to be forwarded to the firewall, preventing asymmetric routing. Asymmetric routing occurs when traffic takes different paths to and from a destination; by ensuring the firewall is the next hop for all outbound traffic, UDRs guarantee symmetric flow through the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VNet peering with gateway transit

    Why it's wrong here

    VNet peering provides connectivity between virtual networks but does not route traffic through a firewall. Gateway transit allows a peered VNet to use the virtual network gateway in the hub, yet that only extends connectivity to on-premises networks; it does not redirect outbound traffic to Azure Firewall. Forcing traffic through the firewall requires UDRs that explicitly set the next hop to the firewall's private IP. Without such routes, system routes remain in effect, so peering alone cannot enforce firewall inspection.

  • ✓

    User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall

    Why this is correct

    A UDR with an address prefix of 0.0.0.0/0 and a next hop type of VirtualAppliance, pointing to the Azure Firewall's private IP, overrides the system default route for all outbound traffic from associated subnets. This forces all internet-bound traffic through the firewall, ensuring stateful inspection and symmetric routing for return packets. UDRs are the core mechanism for forced tunneling and centralized egress control in a hub-and-spoke architecture, making this the correct solution.

  • ✗

    Azure Route Server

    Why it's wrong here

    Azure Route Server uses BGP to dynamically exchange routes between your NVAs and Azure virtual networks, which is useful for route propagation in complex topologies. However, it does not enforce forced tunneling or mandate that outbound traffic traverse a firewall; it only communicates route information. Even with Route Server, you still need UDRs or BGP-learned routes to send traffic to the firewall, and there is no guarantee of symmetric routing or complete inspection. Therefore, Route Server alone cannot secure outbound traffic.

  • ✗

    Azure Firewall Manager to enforce routing policies

    Why it's wrong here

    Azure Firewall Manager is a management and policy orchestration service that centralizes firewall policies, security rules, and network management across multiple Azure Firewall instances. It simplifies deployment and policy consistency, but it does not enforce traffic routing by itself—routing is accomplished through UDRs, which Firewall Manager may automatically generate for a secured virtual hub. Even when Firewall Manager provisions UDRs, the actual enforcement relies on those routes to direct traffic to the firewall, not on the manager's policy definitions. Thus, it is incorrect to say Firewall Manager enforces routing policies; it only helps create the underlying UDRs.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.