AZ-500 Secure networking Practice Question
You have an Azure subscription with multiple virtual networks. You need to centrally manage and enforce security policies for all outbound traffic from virtual machines to the internet. The solution must be able to inspect traffic and log all connections. What should you deploy?
⚠ Common exam trap
Many candidates confuse Azure Firewall with NSGs, assuming NSGs can centrally manage outbound traffic across VNets, but NSGs are decentralized and cannot inspect or log traffic at the application layer or across peered networks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Firewall in a hub virtual network.
Azure Firewall is a managed, cloud-native network security service that provides centralized outbound traffic inspection and logging. It can be deployed in a hub virtual network to enforce security policies across all spoke VMs, inspecting all outbound connections using application (FQDN) and network (IP/port) rules, and logging all traffic to Azure Monitor or Storage. This meets the requirements for central management, traffic inspection, and full connection logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Firewall in a hub virtual network.
Why this is correct
Azure Firewall is a managed, cloud-native firewall service with built-in availability and autoscaling. Deployed as a hub in a hub-and-spoke topology, it can inspect outbound traffic from peered spoke VNets through user-defined routes, and provide stateful network and FQDN-based application rules. It also centralizes logging and integrates with Azure Monitor, satisfying the requirement for outbound inspection and centralized logging.
- ✗
Network security groups (NSGs) on all subnets.
Why it's wrong here
Network security groups (NSGs) can filter traffic based on five-tuple rules at the subnet or network interface level, but they are distributed resources that require per-subnet rule management across many VNets. They do not provide centralized, hub-based inspection of all outbound traffic, nor do they offer application-layer (FQDN) filtering. NSG flow logs can be enabled, but the NSGs themselves lack the built-in centralized logging and management that Azure Firewall provides.
- ✗
Azure Application Gateway with WAF.
Why it's wrong here
Azure Application Gateway is a layer-7 load balancer designed for inbound HTTP/S traffic, with a web application firewall (WAF) to protect web workloads. Its routing and WAF policies apply to requests coming into the gateway from clients, not to outbound traffic leaving virtual networks. Consequently, it cannot inspect or log egress traffic from multiple VNets, so it fails the stated requirement.
- ✗
Azure VPN Gateway with forced tunneling.
Why it's wrong here
Azure VPN Gateway provides encrypted site-to-site or point-to-site connectivity to on-premises networks, and forced tunneling can redirect Internet-bound traffic to an on-premises security device. However, the gateway itself is a tunneling endpoint, not a firewall; it does not parse or log application payloads and has no network or application rules of its own. Even with forced tunneling, you would still need a separate firewall appliance at the tunnel ending, so this option cannot provide centralized outbound inspection and logging by itself.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.