Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

An organization has deployed Azure Firewall and wants to inspect all outbound traffic from a virtual network (VNet) to the internet. The VNet already contains subnets with workloads. What is the required networking configuration to force traffic through Azure Firewall?

⚠ Common exam trap

Test-takers frequently assume NSG rules or DDoS protection can redirect traffic, but only a user-defined route (UDR) with a next hop of the firewall's private IP can force traffic through Azure Firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a route table with a default route (0.0.0.0/0) pointing to the Azure Firewall private IP and associate it with the subnets.

Azure Firewall requires a route table with a default route (0.0.0.0/0) that has the Azure Firewall's private IP as the next hop, associated with each subnet whose traffic must be inspected. This forces all outbound traffic from those subnets to be routed through the firewall, enabling inspection and logging. Without this explicit route, traffic would use the default system route and bypass the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a route table with a default route (0.0.0.0/0) pointing to the Azure Firewall private IP and associate it with the subnets.

    Why this is correct

    A User Defined Route (UDR) with address prefix 0.0.0.0/0 and next hop type 'VirtualAppliance' set to the Azure Firewall's private IP must be associated with each subnet requiring outbound inspection. This custom route overrides Azure's default system route for internet-bound traffic, forcing every egress packet to be forwarded to the firewall for centralized filtering, logging, and NAT. Without this route, the VNet's implicit 0.0.0.0/0 route sends traffic directly to the internet via its default outbound public IP, bypassing the firewall.

  • ✗

    Add a Network Security Group (NSG) rule that allows all outbound traffic and associate it with the subnets.

    Why it's wrong here

    An NSG rule that allows all outbound traffic only grants permission for packets to leave a subnet—it does not alter the packet's next hop or path. NSGs are stateful layer-4 filtering constructs that are evaluated after the routing decision and contain no route-table logic, so they cannot redirect traffic to an Azure Firewall. Because routing is determined solely by the effective route table, an allow-all NSG leaves outbound internet traffic on the default direct egress path rather than sending it through the firewall for inspection.

  • ✗

    Deploy an Application Gateway with Web Application Firewall (WAF) in front of the subnets.

    Why it's wrong here

    Application Gateway with WAF is a layer-7 load balancer and web application firewall designed to protect inbound HTTP/S traffic destined to web applications. It sits in front of a backend pool and can neither act as a next hop nor enforce a default route for outbound packet flows. Its WAF rules inspect inbound client requests for OWASP Top 10 threats, not outbound connections, so deploying it would have no effect on egress traffic and cannot fulfill the requirement to inspect all outbound traffic from the subnets.

  • ✗

    Enable Azure DDoS Protection Standard on the VNet.

    Why it's wrong here

    Enabling Azure DDoS Protection Standard provides always-on monitoring and automatic mitigation of volumetric, protocol, and resource-layer attacks against the VNet's public IP addresses. It operates as an availability and resilience layer, making no routing decisions and offering no visibility into or filtering of legitimate outbound traffic. Rather than inspecting or redirecting egress traffic, it only shields the VNet from being overwhelmed by inbound attack floods, so true outbound inspection still requires a route table pointing to the Azure Firewall or a network virtual appliance.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.