AZ-500 Secure networking Practice Question
Your company has multiple Azure subscriptions managed through Azure Firewall Manager. You need to deploy Azure Firewall policies that apply to all subscriptions in a region. What is the most efficient way to manage this?
⚠ Common exam trap
Test-takers frequently confuse Azure Policy (which enforces resource compliance) with Azure Firewall Manager (which manages firewall policies and rules), leading them to choose option C even though Azure Policy cannot directly apply firewall rule collections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Firewall Manager to create a parent policy and assign it to all firewalls
Azure Firewall Manager provides a centralized management plane for firewall policies across multiple subscriptions and regions. By creating a parent policy and assigning it to all firewalls, you ensure consistent rule enforcement without duplicating effort. This approach is the most efficient because it leverages inheritance, where child policies can override specific rules while inheriting the parent's base configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a separate firewall policy for each subscription
Why it's wrong here
Creating a separate Azure Firewall policy per subscription fails to leverage Firewall Manager's parent/child inheritance model, so the same base rules and settings must be manually replicated across every firewall. This approach inevitably allows configuration drift as teams make local edits, increases administrative overhead, and makes consistent global updates a costly, error-prone rollout rather than a single change to a shared parent policy.
- ✓
Use Azure Firewall Manager to create a parent policy and assign it to all firewalls
Why this is correct
Azure Firewall Manager solves this by letting you create one parent firewall policy that can be associated with Azure Firewalls in any subscription and region, centralizing network rules, application rules, NAT rules, and threat intelligence settings. Each firewall receives the same policy assignment while still supporting child policies for per-firewall customization, making this the correct way to enforce consistent rules across subscriptions without duplicating configuration.
- ✗
Use Azure Policy to enforce firewall rules across subscriptions
Why it's wrong here
Azure Policy is a governance service that can audit whether a firewall policy is assigned or use DeployIfNotExists effects to deploy baseline resources, but it is not designed to author and maintain complex firewall rule collections, rule priorities, or NAT configurations. Expressing detailed network and application rules as Azure Policy definitions would be cumbersome, difficult to reason about, and outside the service's intended role. The proper tool for centrally applying and managing those firewall rules is Azure Firewall Manager policy assignment.
- ✗
Deploy a single network security group (NSG) to all VNets
Why it's wrong here
An NSG is a regional, stateful Layer-4 filtering resource that can only attach to subnets or network interfaces, so a single NSG cannot be associated with an entire Azure Virtual Network and certainly cannot span subscriptions. Even if it could, NSGs lack application-layer filtering, DNS proxy, threat intelligence, and IDPS capabilities, and they provide no centralized cross-subscription policy inheritance. Firewall Manager policies are the only option here that gives consistent, centrally managed firewall rules across multiple subscriptions.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.