AZ-500 Secure networking Practice Question
A company has a hub-spoke network topology in Azure. They need to inspect and filter all traffic flowing between spoke virtual networks for malicious content and require that the inspection is stateful. Which Azure-native service should they deploy in the hub virtual network to meet this requirement?
⚠ Common exam trap
A common pitfall is assuming that NSGs applied to subnets within the hub or spokes can centrally inspect all inter-spoke traffic. While NSGs are stateful, they operate per subnet or NIC and cannot inspect traffic flowing through the hub without explicit routing. Azure Firewall provides the centralized stateful inspection required in a hub-spoke topology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Firewall
Azure Firewall is the correct choice because it is a fully stateful, managed firewall service that can inspect and filter traffic at Layers 3–7. In a hub-spoke topology, deploying Azure Firewall in the hub virtual network allows it to centrally inspect all traffic flowing between spoke virtual networks via forced tunneling (user-defined routes) or through the hub's network virtual appliance, meeting the requirement for stateful inspection of inter-spoke traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Firewall
Why this is correct
Azure Firewall provides stateful inspection and can filter traffic between spoke VNets when configured as a hub. It supports network and application rules, including threat intelligence-based filtering.
- ✗
Network Security Groups (NSG) on the peering connections
Why it's wrong here
NSGs are stateful for individual flows but cannot inspect or filter traffic at the peering level effectively. They are also limited to Layer 3/4 and cannot provide application-layer inspection.
- ✗
Azure Application Gateway with WAF
Why it's wrong here
Application Gateway is a Layer 7 load balancer with Web Application Firewall (WAF) for HTTP/HTTPS traffic. It does not handle general inter-VNet traffic.
- ✗
Azure DDoS Protection Standard
Why it's wrong here
DDoS Protection protects against distributed denial-of-service attacks at the network layer but does not inspect or filter normal traffic between VNets.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.