Force Outbound Traffic Through Azure Firewall with UDR
Traffic from a spoke VNet must reach the internet through a firewall in the hub VNet. What routing configuration is required on the spoke subnets?
⚠ Common exam trap
Many exam-takers confuse NSG rules with routing, thinking a deny rule for 0.0.0.0/0 can force traffic through a firewall, when in fact only a UDR with a specific next hop can redirect traffic to a network virtual appliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A default route to the Azure Firewall private IP or virtual appliance next hop
To force spoke traffic to the internet through a firewall in the hub VNet, you must create a user-defined route (UDR) on the spoke subnet with an address prefix of 0.0.0.0/0 and a next hop of the Azure Firewall's private IP or the virtual appliance's IP. This overrides the default system route that would otherwise send internet-bound traffic directly out via Azure's edge, ensuring all egress traffic is inspected and controlled by the firewall.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A route to Internet with next hop Internet
Why it's wrong here
A user-defined route with the Internet next hop for the 0.0.0.0/0 prefix sends spoke traffic directly through Azure's edge to the public internet, bypassing the firewall or NVA entirely. This defeats the requirement to force all egress through a central security appliance, so no inspection, logging, or filtering can be applied. It should only be used if you intentionally want direct internet connectivity, not for a forced-tunneling architecture.
- ✓
A default route to the Azure Firewall private IP or virtual appliance next hop
Why this is correct
A default route (0.0.0.0/0) with a next hop of the Azure Firewall private IP or the NVA interface is the standard way to implement forced tunneling from a spoke VNet to a hub. This user-defined route overrides Azure's default Internet route and steers all outbound traffic to the firewall, which can then apply rules, NAT, and logging before sending it to the internet. For an NVA, IP forwarding must be enabled on the NIC, and for Azure Firewall, the next hop is simply the firewall's private IP.
- ✗
An NSG deny rule for 0.0.0.0/0
Why it's wrong here
An NSG deny rule for 0.0.0.0/0 blocks all outbound internet traffic at the subnet or NIC level, preventing the spoke from reaching the internet at all. Even though it is a valid security control for egress denial, it does not redirect traffic to a firewall or virtual appliance as required. NSGs are not routing constructs and cannot specify a next hop, so this rule cannot satisfy a forced-tunneling requirement, which demands the traffic be allowed but only through a specific security appliance.
- ✗
A service endpoint policy
Why it's wrong here
A service endpoint policy extends Virtual Network service endpoints and gives granular control over Azure service traffic, such as restricting egress to specific Storage accounts or SQL instances. It does not affect routing or access to the general internet, and it cannot forward traffic to a firewall or virtual appliance. Internet-bound packets from the spoke do not match service endpoint policies, so this mechanism is irrelevant to the stated requirement of reaching the internet via a central firewall.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to design a network security solution for a hub-spoke topology. The hub contains Azure Firewall and Azure Bastion. Spoke VNets contain application workloads. You need to ensure that all traffic from the spokes to the internet is routed through the Azure Firewall. What should you configure?
medium- ✓ A.Add a user-defined route (UDR) on the spoke subnets with 0.0.0.0/0 next hop to the Azure Firewall private IP.
- B.Use service endpoints for internet-bound traffic.
- C.Enable BGP on the spoke VNets and advertise a default route from the hub.
- D.Configure the Azure Firewall to have a default route to the internet.
Why A: A user-defined route (UDR) with 0.0.0.0/0 and next hop set to the Azure Firewall's private IP forces all internet-bound traffic from spoke subnets to be routed through the firewall. This ensures traffic inspection and control by the firewall, which is a key requirement in a hub-spoke topology for centralized security.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.