Azure Firewall Hub-Spoke Inter-Spoke Inspection — Stateful Traffic Filtering
A company uses a hub-spoke network topology in Azure. They need to inspect and filter all traffic flowing between spoke virtual networks for security compliance. Which Azure-native service should be deployed in the hub virtual network to achieve this?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Firewall with a Network Virtual Appliance (NVA), assuming both are equally 'native' or that an NVA is required for deep packet inspection, but Azure Firewall is the native PaaS solution with built-in high availability and no licensing overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Firewall
Azure Firewall is a fully managed, stateful firewall-as-a-service that can inspect and filter traffic between spoke virtual networks when deployed in the hub VNet. It supports application (FQDN) and network (IP/port/protocol) rules, and can enforce security compliance by logging and blocking non-compliant traffic. Unlike a Network Virtual Appliance (NVA), Azure Firewall is a native PaaS service with built-in high availability and auto-scaling, making it the recommended choice for hub-spoke traffic inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Firewall
Why this is correct
Azure Firewall is a fully managed, cloud-native firewall service that provides stateful, L3-L7 inspection. In a hub-spoke topology, it is deployed in the hub VNet and user-defined routes (UDRs) in each spoke direct inter-spoke traffic to the firewall's private IP for centralized filtering. It supports application FQDN rules, network rules, and threat intelligence, making it the correct choice for an Azure-native traffic inspection service.
- ✗
Network Virtual Appliance (NVA)
Why it's wrong here
A Network Virtual Appliance is a third-party VM or containerized firewall (e.g., Palo Alto, Fortinet) that can also inspect spoke-to-spoke traffic if deployed in the hub. However, it is not an Azure-native PaaS service — you must deploy, patch, scale, and manage the VMs yourself, and its availability depends on your HA design. The question specifically asks for an Azure-native solution, so this is not the correct answer.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway is designed to create encrypted IPsec/IKE tunnels between on-premises sites and Azure, or between VNets in a site-to-site configuration. It does not have the ability to inspect or filter traffic based on application-layer rules or enforce security policies between spoke VNets; it is a tunnel endpoint that forwards traffic without examining payloads. In a hub-spoke design, using a VPN Gateway alone would not provide centralized, content-aware traffic control, so it fails the stated requirement.
- ✗
Azure Load Balancer
Why it's wrong here
An Azure Load Balancer is a Layer-4 (TCP/UDP) traffic distributor that sits in the data path and forwards connections to backend pool members based on load-balancing rules and health probes. It does not perform stateful packet inspection, drop packets based on firewall rules, or block specific protocols or domains, and it is not designed to route inter-VNet traffic in a hub inspection architecture. Thus, while it can forward traffic, it lacks the security control needed for filtering between spokes.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.