AZ-500 Secure networking Practice Question
Your company uses Azure Virtual WAN with a secured virtual hub (Azure Firewall). You have branch offices connected via ExpressRoute. You need to ensure that traffic from a branch to a VNet in the same region is inspected by the firewall. You configure the default route (0.0.0.0/0) advertisement from the hub to the branch, but the traffic is not being inspected. What is the most likely reason?
⚠ Common exam trap
Watch out — candidates often assume configuring the default route (0.0.0.0/0) is sufficient to inspect all traffic, but Azure Virtual WAN requires explicit routing intent for private traffic to force branch-to-VNet flows through the firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Routing intent for private traffic is not enabled.
Routing intent for private traffic must be enabled on the Virtual WAN hub to ensure that inter-VNet and branch-to-VNet traffic (private IP ranges) is routed through the Azure Firewall. Without routing intent, only internet-bound traffic (0.0.0.0/0) is forced through the firewall by the default route, while private traffic between branches and VNets bypasses inspection. Enabling routing intent for private traffic overrides the default behavior and injects the firewall as the next hop for all private traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'Inter-hub' setting is disabled.
Why it's wrong here
The 'Inter-hub' setting in Azure Virtual WAN controls transit routing between hubs, enabling traffic to flow from one hub to another through Microsoft's backbone. It has no effect on how a branch site's VPN connection routes traffic to a VNet attached to the same hub. Branch-to-VNet traffic inspection requires routing intent, not the Inter-hub toggle, so disabling Inter-hub would not cause the firewall to be bypassed in this scenario.
- ✗
The branch does not have a route table associated with the connection.
Why it's wrong here
Branch connections in Virtual WAN do not require an explicitly associated route table for basic connectivity; Virtual WAN automatically manages route propagation from hubs to branch sites. If the branch can reach the VNet at all, the route exists regardless of route table associations. The correct fix for forcing branch-to-VNet traffic through the firewall is enabling routing intent, not attaching a route table to the branch connection.
- ✓
Routing intent for private traffic is not enabled.
Why this is correct
Routing intent is the control plane mechanism in Azure Virtual WAN that lets you designate an Azure Firewall or a network virtual appliance as the next hop for private traffic, including branch-to-VNet traffic. Without a routing intent policy for private traffic, the Virtual WAN hub uses its default routing behavior, which sends packets directly from the branch gateway to the VNet's connection, bypassing the secured hub firewall entirely. Therefore, enabling routing intent for private traffic is the required action to restore firewall inspection.
- ✗
The VNet has a network virtual appliance (NVA) that overrides the firewall.
Why it's wrong here
There is no indication that a network virtual appliance (NVA) exists in the scenario, and an NVA inside a spoke VNet would not automatically override hub-level routing. Even if an NVA were present, branch traffic arriving at the Virtual WAN hub would only be sent to that NVA if a UDR or routing intent directed it there; otherwise, the hub routes directly to the VNet's address space. The failure is not caused by an NVA overriding the firewall but by the absence of routing intent to steer traffic through the secured hub's firewall.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.