AZ-500 Secure networking Practice Question
Your organization uses Azure Virtual Network Manager (AVNM) to manage network groups. You need to ensure that all virtual networks in a network group are automatically peered with a hub VNet. Which AVNM configuration should you use?
⚠ Common exam trap
It's easy for candidates to confuse a network group (a logical container) with a connectivity configuration (which defines the actual topology and peering), leading them to select Option B without realizing the configuration type is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a connectivity configuration with Hub and Spoke topology
To automatically peer all virtual networks in a network group with a hub VNet, you need a connectivity configuration with Hub and Spoke topology. AVNM's connectivity configuration defines the network topology (e.g., hub-and-spoke or mesh) and automatically creates the necessary VNet peering connections between the hub and all spoke VNets in the assigned network group, without manual peering setup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a connectivity configuration with Hub and Spoke topology
Why this is correct
In Azure Virtual Network Manager, a connectivity configuration defines the actual network topology you want to establish. When you select Hub and Spoke, AVNM automatically creates VNet peering between the hub VNet and all spoke VNets assigned to that configuration, eliminating the need for manual peering. This configuration also manages transitive routing, so spokes can communicate through the hub without requiring individual peerings between every spoke. Thus, creating a connectivity configuration with hub-and-spoke topology is the correct and direct mechanism to automate peering in AVNM.
- ✗
Create a network group and assign it to a connectivity configuration
Why it's wrong here
A network group is merely a logical container that identifies a set of VNets based on conditions like subscription, region, or tag. Assigning a network group to a connectivity configuration is necessary for scope, but the network group itself does not create any peering. The connectivity configuration, not the network group, is what specifies the topology (e.g., hub-and-spoke) and triggers AVNM to provision the actual VNet peerings. Therefore, simply creating a network group without a connectivity configuration will leave VNets isolated.
- ✗
Create a security admin configuration
Why it's wrong here
A security admin configuration in AVNM is used to enforce security rules—such as allow or deny traffic for specific ports, protocols, or IP addresses—across your virtual networks. While security admin rules can protect traffic between VNets, they do not establish connectivity or create peering relationships. Security configurations are additive to network connectivity, not a substitute for the connectivity configuration that builds the topology. Hence, this option does not address the requirement to automate VNet peering.
- ✗
Use Azure Policy to enforce peering
Why it's wrong here
Azure Policy can enforce compliance and audit configurations, and it can even deploy resources or modify settings via DeployIfNotExists policies. However, Azure Policy does not natively create or manage VNet peering; it can only detect or remediate drift by deploying a known peering resource if one is defined. To automate peering dynamically across many VNets, Azure Virtual Network Manager's connectivity configuration is the purpose-built service. Thus, relying solely on Azure Policy is not the correct way to establish hub-and-spoke peering in AVNM.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.