AZ-500 Secure networking Practice Question
Your company uses Azure Firewall Premium with TLS inspection to filter outbound traffic from Azure VMs. Users report that some websites are not loading. You have configured the firewall to inspect traffic to *.microsoft.com. What is the most likely cause of the issue?
⚠ Common exam trap
Watch out — candidates often assume the firewall rule is misconfigured or that HTTPS inspection is impossible, when in fact the core issue is client-side certificate trust, not firewall policy or protocol capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The client does not trust the certificate presented by the firewall during TLS inspection.
Azure Firewall Premium with TLS inspection acts as a man-in-the-middle (MITM) proxy. It decrypts outbound HTTPS traffic, inspects it, then re-encrypts it using a certificate signed by an internal CA. If the client VM does not trust the firewall's internal CA certificate (e.g., it is not installed in the Trusted Root Certification Authorities store), the browser will reject the connection, causing websites to fail to load even though the firewall rule is correctly configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall rule for *.microsoft.com is misconfigured.
Why it's wrong here
The application rule for *.microsoft.com is correctly scoped and permitted; the client's failure occurs during the TLS handshake, before the firewall applies any FQDN-based action on decrypted traffic. If the rule were misconfigured, the symptom would be a denial of connectivity (e.g., timeout or RST), not a certificate validation error generated by the client's TLS stack. Because the requested location matches the permitted FQDN, the rule cannot be the source of the certificate-trust failure.
- ✗
The firewall cannot inspect HTTPS traffic.
Why it's wrong here
Azure Firewall Premium does support TLS inspection; it can terminate inbound/outbound TLS, decrypt the payload, apply application and network rules, then re-encrypt with a certificate supplied from your own key vault or generated by a configured CA. Therefore, 'cannot inspect HTTPS traffic' is factually incorrect. The error the client sees indicates that inspection is occurring—the firewall is presenting its certificate—but the client's trust store does not recognize the issuing CA as valid.
- ✗
The firewall is blocking HTTP traffic.
Why it's wrong here
HTTP traffic is cleartext and does not involve certificates; turning off or blocking HTTP cannot produce a TLS certificate trust/presentation error. If the firewall were blocking HTTP, the user would see a plain connection failure, such as ERR_CONNECTION_REFUSED or a TCP reset, rather than a warning that the certificate authority is not trusted. Since the reported issue is exclusively on HTTPS sessions, blaming HTTP blocking is a category mistake for this symptom.
- ✓
The client does not trust the certificate presented by the firewall during TLS inspection.
Why this is correct
During TLS inspection, Azure Firewall Premium acts as a proxy: it establishes the TLS connection from the client and presents a certificate issued by your organization's private CA (or custom root). Every client that sends HTTPS through this inspection path must trust that CA certificate in its local certificate store; otherwise the browser or application aborts the handshake with a certificate authority invalid / unknown issuer error. Because the rule configuration and the firewall's inspection capability are both valid, the missing trust anchor on the client is the only remaining explanation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.