Courseiva
Secure networkinghardMultiple ChoiceObjective-mapped

AZ-500 Secure networking Practice Question

Your organization has multiple Azure subscriptions connected via a hub-spoke topology using Azure Firewall in the hub. You need to ensure that traffic between spoke VNets is routed through the firewall for inspection. You configure user-defined routes (UDRs) on the spoke subnets. However, traffic between spokes is still bypassing the firewall. What is the most likely reason?

⚠ Common exam trap

The trap is that candidates may think 'Use remote gateway' must be enabled to force traffic through the hub firewall; in fact, it should remain disabled because it applies to VPN/ExpressRoute gateways, not Azure Firewall. UDRs are the correct mechanism for routing spoke-to-spoke traffic through the firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The 'Use remote gateway' setting is disabled on the spoke VNet peering.

In a hub-spoke topology with Azure Firewall, the 'Use remote gateway' setting on the spoke VNet peering must be disabled. This setting is only for using a VPN or ExpressRoute gateway in the hub; it does not enable routing through Azure Firewall. With this setting disabled, the configured UDRs on the spoke subnets can direct spoke-to-spoke traffic to the firewall for inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Firewall does not support traffic between spoke VNets.

    Why it's wrong here

    Azure Firewall supports transit traffic between spokes.

  • The UDR on the firewall subnet does not include the spoke address spaces.

    Why it's wrong here

    UDR on firewall subnet is not required for spoke-to-spoke; firewall handles routing.

  • The 'Allow gateway transit' setting is disabled on the spoke peering.

    Why it's wrong here

    'Allow gateway transit' is configured on the hub peering, not spoke.

  • The 'Use remote gateway' setting is disabled on the spoke VNet peering.

    Why this is correct

    Spoke VNets must use remote gateway to route traffic through the hub firewall.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 194 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.