SC-100 Design security solutions for infrastructure Practice Question
You are designing a zero-trust network architecture for a hybrid environment using Azure Virtual WAN. You need to secure all traffic between on-premises sites and Azure virtual networks using Microsoft's security services. The solution should include next-generation firewall capabilities and TLS inspection. What should you deploy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Azure Firewall Premium as the secured hub in Virtual WAN.
Azure Firewall Premium is the correct choice because it is the only Azure Firewall SKU that provides next-generation firewall capabilities such as TLS inspection, IDPS, and URL filtering, and it can be deployed directly as the secured hub in Azure Virtual WAN to protect all on-premises-to-Azure and inter-hub traffic. Azure Firewall Standard lacks TLS inspection and IDPS, so it cannot meet the stated requirement. A third-party NVA in a spoke virtual network would require custom routing and does not natively integrate as the Virtual WAN secured hub, adding complexity and not using Microsoft's security services as requested. Application Gateway with WAF is a Layer 7 web traffic load balancer for HTTP/HTTPS applications, not a network firewall for securing all hybrid traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a third-party NVA in a spoke virtual network and route traffic through it.
Why it's wrong here
Deploying a third-party NVA in a spoke virtual network forces you to manage complex user-defined routes (UDRs) and all traffic flows manually. It also breaks central policy enforcement — each spoke becomes a separate point of failure, and scaling or patching the NVA requires additional operational effort. Unlike a Virtual WAN secured hub, this design does not provide a single, centrally managed firewall plane for all branch-to-branch and VNet-to-VNet traffic, making end-to-end inspection inconsistent and hard to audit.
- ✗
Deploy Azure Firewall Standard as the secured hub in Virtual WAN.
Why it's wrong here
Azure Firewall Standard does support L3-L7 filtering and is natively integrated with Virtual WAN, but it cannot perform TLS inspection. In a zero trust architecture, most east-west and north-south traffic is encrypted, so without the ability to decrypt, inspect, and re-encrypt HTTPS flows, you cannot enforce FQDN-based allowlists or detect hidden threats. Standard lacks the Premium SKU's IDPS and advanced TLS inspection capabilities, so it would leave a critical blind spot for encrypted threats — making it an incorrect choice for this scenario.
- ✗
Deploy Azure Application Gateway with WAF in each virtual network.
Why it's wrong here
Azure Application Gateway with WAF is a Layer-7 load balancer specialized for inbound HTTP(S) traffic to web applications, not a general-purpose network firewall. Deploying it in each VNet addresses only north-south web-facing traffic and provides no centralized control or inspection for inter-spoke, on-premises, or VPN traffic. This siloed, per-VNet approach fails to deliver the hub-and-spoke connectivity and unified policy enforcement that Azure Virtual WAN's secured hub provides, and it cannot handle non-HTTP traffic or network-layer filtering.
- ✓
Deploy Azure Firewall Premium as the secured hub in Virtual WAN.
Why this is correct
Azure Firewall Premium is the right choice because it integrates natively as the secured hub in Virtual WAN, enabling centralized routing and policy enforcement for all traffic through the hub. It provides TLS inspection, IDPS, FQDN filtering, and threat intelligence — capabilities essential for a zero trust architecture. As a fully managed, auto-scalable service, it removes the operational burden of third-party NVAs while ensuring encrypted traffic is decrypted, inspected, and re-encrypted to enforce allowlisting and detect malicious activity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.