Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

Your organization uses Azure Virtual WAN. You need to secure traffic between a spoke VNet and an on-premises site that connects via a Virtual WAN VPN gateway. What is the best way to inspect traffic?

⚠ Common exam trap

Many exam-takers assume deploying a firewall directly in the spoke VNet (Option A) is sufficient, but they overlook that Virtual WAN's automatic routing bypasses spoke-based firewalls unless complex and unsupported UDRs are configured, making the secured virtual hub the only native and supported solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Firewall Manager to deploy a secured virtual hub.

Azure Firewall Manager enables you to deploy a secured virtual hub, which centrally manages and routes traffic between Virtual WAN spokes and on-premises sites through Azure Firewall for inspection. This is the best approach because it provides a scalable, hub-and-spoke architecture with forced tunneling and routing policies that ensure all traffic between the spoke VNet and the on-premises site is inspected without requiring additional NVAs or complex user-defined routes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Azure Firewall in the spoke VNet.

    Why it's wrong here

    Azure Firewall deployed inside a spoke VNet is not in the transit path of Virtual WAN. Spoke VNet connections route inter-spoke and branch traffic through the virtual hub's routing infrastructure, not through arbitrary spoke resources, so a firewall in a spoke will only inspect traffic that is explicitly sent to it via custom user-defined routes. Without such routes, most Virtual WAN traffic bypasses it, and it cannot provide centralized security enforcement for the entire WAN.

  • ✗

    Deploy a third-party NVA in the spoke VNet.

    Why it's wrong here

    A third-party NVA in a spoke VNet is not automatically part of Virtual WAN's data path. To inspect traffic, you must create route tables and static next hops to reroute traffic to the NVA's IP address, and even then it won't secure branch-to-branch or hub-to-hub traffic unless every connection is painstakingly configured. The secured virtual hub approach places a firewall directly in the hub, making it the default next hop for all Virtual WAN connections, which is far simpler and more reliable than trying to force an NVA into a non-default position.

  • ✗

    Apply NSG rules on the spoke subnet.

    Why it's wrong here

    NSGs operate at the network layer on subnets or virtual machine NICs and only filter traffic that enters or leaves the specific spoke subnet. Traffic flowing from one spoke to another or from a branch to a spoke traverses the virtual hub and is not subject to the spoke subnet's NSG unless it is explicitly destined for a VM in that subnet. NSGs also lack application-layer capabilities such as FQDN filtering, TLS inspection, and centralized policy management, so they cannot act as the primary security control for Virtual WAN.

  • ✓

    Use Azure Firewall Manager to deploy a secured virtual hub.

    Why this is correct

    Azure Firewall Manager integrates natively with Virtual WAN to deploy a secured virtual hub, meaning Azure Firewall is placed directly in the hub's transit path where all inter-spoke, branch-to-spoke, and branch-to-branch traffic converges. The firewall's routing is automatically managed by the hub's route tables, and Firewall Manager provides a single control plane to apply and audit security policies across all hubs and regions. This is the correct way to secure Virtual WAN because it centralizes inspection without requiring per-spoke configuration or custom user-defined routes.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.