AZ-500 Secure networking Practice Question
You are a security engineer at Northwind Traders. The company has an Azure subscription with a virtual network named VNet1. You need to ensure that all outbound internet traffic from VNet1 is inspected by a central security appliance before leaving the network. You also need to log all traffic for auditing. The solution must minimize administrative effort and support scaling. What should you deploy?
⚠ Common exam trap
The trap here is assuming that network security groups alone can provide central inspection and logging of outbound traffic, when they are merely basic access control lists without payload inspection or centralized routing control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Firewall in a hub virtual network, with user-defined routes (UDRs) in VNet1 pointing to the firewall's private IP address as the next hop for 0.0.0.0/0.
Azure Firewall is a managed, cloud-native network security service that provides central inspection, logging, and scalability. By deploying it in a hub and using user-defined routes in VNet1 to direct all outbound traffic (0.0.0.0/0) to the firewall's private IP, you ensure every packet is inspected and logged. This design minimizes administrative effort because Azure manages the firewall infrastructure and scaling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network security groups (NSGs) on each subnet with rules to allow only required outbound traffic, and enable NSG flow logs.
Why it's wrong here
NSGs are basic stateful filters that can restrict traffic and flow logs can capture information, but they do not inspect payloads or provide central management. They also cannot force traffic through a specific appliance. This approach does not meet the requirement for a central security appliance to inspect all outbound traffic.
- ✓
Azure Firewall in a hub virtual network, with user-defined routes (UDRs) in VNet1 pointing to the firewall's private IP address as the next hop for 0.0.0.0/0.
Why this is correct
Azure Firewall is a managed, scalable cloud-native firewall that provides central inspection and logging. By creating a UDR in VNet1 that routes 0.0.0.0/0 to the firewall's private IP, all outbound internet traffic is forced through the firewall. This meets the inspection and logging needs with minimal management overhead and supports autoscaling.
- ✗
Azure VPN Gateway with forced tunneling configured to route all traffic through an on-premises firewall.
Why it's wrong here
VPN Gateway with forced tunneling can route traffic to on-premises, but it requires an on-premises firewall and VPN connectivity, which increases administrative effort and may not scale elastically. The scenario asks to minimize effort and support scaling, which Azure Firewall natively provides without on-premises dependencies.
- ✗
Azure Application Gateway with Web Application Firewall (WAF) and configure custom routing rules to send all outbound traffic to the gateway.
Why it's wrong here
Application Gateway is a layer 7 load balancer for inbound HTTP/HTTPS traffic, not an outbound internet inspection solution. WAF protects web applications from inbound attacks. It cannot route or inspect arbitrary outbound traffic from VNet1, so it does not satisfy the scenario's requirement for central outbound inspection.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.