AZ-305 Design infrastructure solutions Practice Question
A company uses Azure Firewall to secure outbound traffic from a hub virtual network. The security team reports that some traffic is bypassing the firewall because of asymmetric routing. You need to design a solution to force all outbound traffic through the firewall. What should you implement?
⚠ Common exam trap
Many candidates confuse Azure Firewall Manager's policy enforcement with actual traffic routing, but Firewall Manager does not create UDRs; it only manages firewall policies, and UDRs are still required to direct traffic to the firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall
User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall as the next hop are the correct solution because they override the system default route and force all outbound traffic from subnets to be forwarded to the firewall, preventing asymmetric routing. Asymmetric routing occurs when traffic takes different paths to and from a destination; by ensuring the firewall is the next hop for all outbound traffic, UDRs guarantee symmetric flow through the firewall.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VNet peering with gateway transit
Why it's wrong here
VNet peering provides connectivity between virtual networks but does not route traffic through a firewall. Gateway transit allows a peered VNet to use the virtual network gateway in the hub, yet that only extends connectivity to on-premises networks; it does not redirect outbound traffic to Azure Firewall. Forcing traffic through the firewall requires UDRs that explicitly set the next hop to the firewall's private IP. Without such routes, system routes remain in effect, so peering alone cannot enforce firewall inspection.
- ✓
User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall
Why this is correct
A UDR with an address prefix of 0.0.0.0/0 and a next hop type of VirtualAppliance, pointing to the Azure Firewall's private IP, overrides the system default route for all outbound traffic from associated subnets. This forces all internet-bound traffic through the firewall, ensuring stateful inspection and symmetric routing for return packets. UDRs are the core mechanism for forced tunneling and centralized egress control in a hub-and-spoke architecture, making this the correct solution.
- ✗
Azure Route Server
Why it's wrong here
Azure Route Server uses BGP to dynamically exchange routes between your NVAs and Azure virtual networks, which is useful for route propagation in complex topologies. However, it does not enforce forced tunneling or mandate that outbound traffic traverse a firewall; it only communicates route information. Even with Route Server, you still need UDRs or BGP-learned routes to send traffic to the firewall, and there is no guarantee of symmetric routing or complete inspection. Therefore, Route Server alone cannot secure outbound traffic.
- ✗
Azure Firewall Manager to enforce routing policies
Why it's wrong here
Azure Firewall Manager is a management and policy orchestration service that centralizes firewall policies, security rules, and network management across multiple Azure Firewall instances. It simplifies deployment and policy consistency, but it does not enforce traffic routing by itself—routing is accomplished through UDRs, which Firewall Manager may automatically generate for a secured virtual hub. Even when Firewall Manager provisions UDRs, the actual enforcement relies on those routes to direct traffic to the firewall, not on the manager's policy definitions. Thus, it is incorrect to say Firewall Manager enforces routing policies; it only helps create the underlying UDRs.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.