Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are the security architect for a company that uses Azure Firewall to protect a hub-and-spoke network topology. The company requires that all outbound traffic from the spoke virtual networks be inspected by the firewall. You need to recommend a solution that ensures traffic is forced through the firewall without requiring complex routing configurations on each spoke. What should you recommend?

⚠ Common exam trap

The trap here is assuming that UDRs on each spoke are the only way to force traffic through Azure Firewall, overlooking the automated routing capabilities of Azure Virtual WAN with routing intent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Virtual WAN with a secured virtual hub and associate the spoke virtual networks to the hub. Configure routing intent to direct traffic to the firewall.

Azure Virtual WAN with a secured virtual hub provides a scalable and centralized way to route traffic through Azure Firewall. By associating spoke virtual networks to the hub and configuring routing intent, traffic is automatically directed to the firewall without the need for manual UDRs on each spoke. This reduces administrative complexity and ensures consistent inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Azure Firewall forced tunneling and configure the spokes to use the firewall as the next hop via BGP.

    Why it's wrong here

    Forced tunneling in Azure Firewall is used to route internet-bound traffic to an on-premises firewall or virtual appliance, not to route spoke traffic through the Azure Firewall. BGP can propagate routes, but it requires configuration on the spokes and may not be supported in all scenarios, adding complexity.

  • ✗

    Configure user-defined routes (UDRs) on each spoke subnet to route 0.0.0.0/0 to the Azure Firewall private IP address.

    Why it's wrong here

    UDRs are a valid method to force traffic through Azure Firewall, but they require configuration on each spoke subnet. This approach can become complex to manage as the number of spokes grows, and it does not meet the requirement of avoiding complex routing configurations on each spoke. It is a manual and error-prone solution.

  • ✓

    Use Azure Virtual WAN with a secured virtual hub and associate the spoke virtual networks to the hub. Configure routing intent to direct traffic to the firewall.

    Why this is correct

    Azure Virtual WAN with a secured virtual hub allows you to associate spoke virtual networks and use routing intent to automatically route traffic through the firewall. This eliminates the need for manual UDRs on each spoke, providing a centralized and scalable solution that meets the requirement of minimal complexity.

  • ✗

    Deploy Azure Firewall in each spoke virtual network and configure peering between spokes to route traffic through the firewalls.

    Why it's wrong here

    Deploying a firewall in each spoke increases cost and management overhead, and peering between spokes does not automatically force traffic through the firewalls. This design is not scalable and does not meet the requirement of a centralized inspection point without complex routing.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.