AZ-500 Secure networking Practice Question
A company has a hub-and-spoke network topology in Azure. The hub virtual network contains an Azure Firewall and a VPN gateway. Spoke virtual networks are peered to the hub. The security team wants to ensure that all outbound internet traffic from VMs in the spokes flows through the Azure Firewall. What should be configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a route table with a default route (0.0.0.0/0) to the Azure Firewall private IP and associate it with the spoke subnets.
To force all outbound internet traffic from spoke VNets through the Azure Firewall, you must create a route table with a default route (0.0.0.0/0) that has the Azure Firewall's private IP as the next hop, and associate that route table with the subnets in the spoke VNets. This overrides the default system route and sends all internet-bound traffic to the firewall. Option B is wrong because forced tunneling on a VPN gateway is used to route on-premises traffic, not to direct spoke traffic through the firewall. Option C is wrong because the route table should be associated with spoke subnets, not the hub subnet. Option D is wrong because NSGs do not support next-hop routing; they filter traffic, not direct it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a route table with a default route (0.0.0.0/0) to the Azure Firewall private IP and associate it with the spoke subnets.
Why this is correct
In a hub-and-spoke topology, the correct way to force all outbound internet traffic from spoke VMs through an Azure Firewall is to create a route table with a 0.0.0.0/0 route whose next hop is set to the firewall's private IP address, then associate that route table with each spoke subnet. This UDR overrides the default system route for internet traffic, and because the spoke VNet is peered to the hub, packets can reach the firewall through the peering. Additionally, the firewall must be configured with its own allow rules and SNAT so replies return symmetrically to avoid asymmetric routing.
- ✗
Configure forced tunneling on the VPN gateway to route all traffic through the Azure Firewall.
Why it's wrong here
Forced tunneling on a VPN gateway is a feature that redirects Internet-bound traffic originating from on-premises sites through the VPN tunnel into Azure for inspection; it does not affect traffic that originates inside spoke VMs. Spoke VM traffic never enters the VPN gateway unless you explicitly route it there with a UDR, and even then forced tunneling is a VPN gateway property set on the connection, not a mechanism for steering internal Azure traffic to a firewall. Therefore it cannot be used to route spoke subnets' internet traffic through Azure Firewall.
- ✗
Create a route table with a default route to the VPN gateway and associate it with the hub subnet.
Why it's wrong here
Placing a default route next-hop to the VPN gateway and associating it with the hub subnet only affects the hub subnet itself, because route tables are not transitive across peered VNets—spoke subnets continue to use their own system routes. Furthermore, a VPN gateway cannot act as a generic forwarding appliance for arbitrary internet traffic; its next-hop IP is not a virtual appliance that forwards packets to the internet, and it lacks the stateful inspection and NAT capability of a firewall. The route table must be applied to spoke subnets and point to the Azure Firewall's private IP.
- ✗
Configure an NSG on the spoke subnets with a rule that sends traffic to the Azure Firewall.
Why it's wrong here
An NSG is a traffic-filtering layer that evaluates allow/deny rules based on source/destination IP, port, and protocol—it cannot specify a next hop, change routing, or redirect traffic to another device. Network Security Groups operate only after a packet's route has been determined, and they do not have any concept of forwarding or next-hop selection. Azure Firewall as a next hop must be expressed in a route table (UDR), never in an NSG rule, so configuring an NSG rule with the firewall as the destination would not achieve the intended routing.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.