Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

Your company has an Azure subscription with several VNets. You deploy Azure Firewall in a hub VNet. You need to ensure that all traffic from spoke VNets to the internet goes through the firewall. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse Azure Firewall policy (which controls allowed traffic) with routing (which directs traffic to the firewall), leading them to select Option C, but without a UDR, traffic never reaches the firewall for policy to be applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a route table with a default route (0.0.0.0/0) to the Azure Firewall private IP and associate it with the spoke subnets.

To force all internet-bound traffic from spoke VNets through Azure Firewall, you must create a user-defined route (UDR) with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP address as the next hop. This route table must be associated with the subnets in the spoke VNets, ensuring that any traffic destined for the internet is redirected to the firewall for inspection and policy enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure forced tunneling on the spoke VNet gateways.

    Why it's wrong here

    Forced tunneling is a gateway-level feature that applies only to a VPN or ExpressRoute gateway's GatewaySubnet, not to standard VM subnets in a spoke VNet. It redirects site-to-site or Point-to-Site traffic toward an on-premises endpoint via a default route, but it does not change the effective route for regular spoke workloads to send traffic to the Azure Firewall's private IP. In a hub-and-spoke topology without a gateway in the spoke, this option is simply not applicable, and even with a gateway, the next hop would be an on-premises target, not the firewall.

  • ✗

    Enable VNet peering to the hub VNet.

    Why it's wrong here

    VNet peering establishes IP-level connectivity between the hub and spoke address spaces, but Azure's system routes still determine how traffic flows after peering is enabled. A peering relationship does not insert the Azure Firewall as a next hop; spoke VMs will continue to use Azure's default 0.0.0.0/0 route and egress via the platform's SNAT. While peering is necessary for the hub and spoke to communicate, it is not a routing control—you still need a user-defined route that explicitly sends outbound traffic to the firewall's private IP.

  • ✗

    Apply an Azure Firewall policy that denies internet access for spoke VNets.

    Why it's wrong here

    Azure Firewall policy rules are evaluated only for traffic that actually arrives at the firewall's data plane. If the spoke subnets retain Azure's default system route for 0.0.0.0/0, all internet-bound traffic is sent directly to the platform's front-end SNAT and never reaches the firewall, so a rule denying internet access is never applied. This is a control-plane/logical configuration; it cannot influence where packets are routed. Only a UDR with next hop 'VirtualAppliance' pointing to the firewall's private IP will bring the traffic into the firewall for evaluation, at which point the deny rule will take effect.

  • ✓

    Create a route table with a default route (0.0.0.0/0) to the Azure Firewall private IP and associate it with the spoke subnets.

    Why this is correct

    This is the correct approach: create a route table containing a default route 0.0.0.0/0 with the next hop type set to VirtualAppliance and the next hop address set to the Azure Firewall's private IP. Associate that route table with all spoke subnets, which overrides Azure's system route for 0.0.0.0/0 and forces every outbound packet to be forwarded to the firewall first. The firewall then inspects the traffic using network and application rules, providing the intended centralized filtering for internet-bound and cross-premises traffic.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.