Courseiva
Secure networking →hardMultiple Choice

AZ-500 Secure networking Practice Question

A company has a hub-spoke network topology in Azure. They need to inspect and filter all traffic flowing between spoke virtual networks for malicious content and require that the inspection is stateful. Which Azure-native service should they deploy in the hub virtual network to meet this requirement?

⚠ Common exam trap

A common pitfall is assuming that NSGs applied to subnets within the hub or spokes can centrally inspect all inter-spoke traffic. While NSGs are stateful, they operate per subnet or NIC and cannot inspect traffic flowing through the hub without explicit routing. Azure Firewall provides the centralized stateful inspection required in a hub-spoke topology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Firewall

Azure Firewall is the correct choice because it is a fully stateful, managed firewall service that can inspect and filter traffic at Layers 3–7. In a hub-spoke topology, deploying Azure Firewall in the hub virtual network allows it to centrally inspect all traffic flowing between spoke virtual networks via forced tunneling (user-defined routes) or through the hub's network virtual appliance, meeting the requirement for stateful inspection of inter-spoke traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Firewall

    Why this is correct

    Azure Firewall provides stateful inspection and can filter traffic between spoke VNets when configured as a hub. It supports network and application rules, including threat intelligence-based filtering.

  • ✗

    Network Security Groups (NSG) on the peering connections

    Why it's wrong here

    NSGs are stateful for individual flows but cannot inspect or filter traffic at the peering level effectively. They are also limited to Layer 3/4 and cannot provide application-layer inspection.

  • ✗

    Azure Application Gateway with WAF

    Why it's wrong here

    Application Gateway is a Layer 7 load balancer with Web Application Firewall (WAF) for HTTP/HTTPS traffic. It does not handle general inter-VNet traffic.

  • ✗

    Azure DDoS Protection Standard

    Why it's wrong here

    DDoS Protection protects against distributed denial-of-service attacks at the network layer but does not inspect or filter normal traffic between VNets.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.