AZ-500 Secure networking Practice Question
Your organization has multiple Azure subscriptions connected via a hub-spoke topology using Azure Firewall in the hub. You need to ensure that traffic between spoke VNets is routed through the firewall for inspection. You configure user-defined routes (UDRs) on the spoke subnets. However, traffic between spokes is still bypassing the firewall. What is the most likely reason?
⚠ Common exam trap
The trap is that candidates may think 'Use remote gateway' must be enabled to force traffic through the hub firewall; in fact, it should remain disabled because it applies to VPN/ExpressRoute gateways, not Azure Firewall. UDRs are the correct mechanism for routing spoke-to-spoke traffic through the firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'Use remote gateway' setting is disabled on the spoke VNet peering.
In a hub-spoke topology with Azure Firewall, the 'Use remote gateway' setting on the spoke VNet peering must be disabled. This setting is only for using a VPN or ExpressRoute gateway in the hub; it does not enable routing through Azure Firewall. With this setting disabled, the configured UDRs on the spoke subnets can direct spoke-to-spoke traffic to the firewall for inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall does not support traffic between spoke VNets.
Why it's wrong here
Azure Firewall supports transit traffic between spokes.
- ✗
The UDR on the firewall subnet does not include the spoke address spaces.
Why it's wrong here
UDR on firewall subnet is not required for spoke-to-spoke; firewall handles routing.
- ✗
The 'Allow gateway transit' setting is disabled on the spoke peering.
Why it's wrong here
'Allow gateway transit' is configured on the hub peering, not spoke.
- ✓
The 'Use remote gateway' setting is disabled on the spoke VNet peering.
Why this is correct
Spoke VNets must use remote gateway to route traffic through the hub firewall.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 194 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.