You have an Azure subscription with multiple virtual networks. You need to centrally manage and enforce security policies for all outbound traffic from virtual machines to the internet. The solution must be able to inspect traffic and log all connections. What should you deploy?
Azure Firewall is a managed, cloud-native firewall service with built-in availability and autoscaling. Deployed as a hub in a hub-and-spoke topology, it can inspect outbound traffic from peered spoke VNets through user-defined routes, and provide stateful network and FQDN-based application rules. It also centralizes logging and integrates with Azure Monitor, satisfying the requirement for outbound inspection and centralized logging.
Why this answer
Azure Firewall is a managed, cloud-native network security service that provides centralized outbound traffic inspection and logging. It can be deployed in a hub virtual network to enforce security policies across all spoke VMs, inspecting all outbound connections using application (FQDN) and network (IP/port) rules, and logging all traffic to Azure Monitor or Storage. This meets the requirements for central management, traffic inspection, and full connection logging.
Exam trap
The trap here is that candidates often confuse Azure Firewall with NSGs, assuming NSGs can centrally manage outbound traffic across VNets, but NSGs are decentralized and cannot inspect or log traffic at the application layer or across peered networks.
How to eliminate wrong answers
Option B is wrong because Network Security Groups (NSGs) operate at the subnet or NIC level, provide only stateful packet filtering (no deep packet inspection), and do not log individual connections with full details like source/destination IPs and ports by default; they also cannot centrally enforce policies across multiple virtual networks. Option C is wrong because Azure Application Gateway with WAF is a Layer 7 load balancer designed for inbound HTTP/HTTPS traffic protection, not for outbound traffic inspection or logging of all connections. Option D is wrong because Azure VPN Gateway with forced tunneling only redirects outbound traffic to an on-premises network for inspection, but it does not inspect traffic itself, nor does it log connections natively; it requires additional on-premises firewall infrastructure.