Courseiva

SC-100 User Defined Route (UDR) Practice Question

Your organization is planning to deploy a new web application on Azure VMs. The security team requires that all incoming traffic to the VMs be inspected by a network virtual appliance (NVA) before reaching the VMs. Which Azure networking solution should you use to route traffic through the NVA?

⚠ Common exam trap

Candidates often confuse Azure Firewall (a managed firewall service) with a routing mechanism. UDRs are the correct way to direct traffic through an NVA, not Azure Firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User Defined Routes (UDRs)

User Defined Routes (UDRs) are the correct choice because they let you override Azure's default system routes and force traffic to be sent to a specific next hop, such as the private IP of a network virtual appliance, so packets are inspected before reaching the VMs. In this scenario, the security team requires traffic to pass through the NVA, which is exactly what a UDR with the NVA as the next hop accomplishes. Azure Firewall (A) is itself a managed firewall service, not the routing mechanism used to redirect traffic to a third-party NVA. Azure Load Balancer (B) distributes traffic across endpoints but does not control routing paths, and Network Security Groups (C) only filter traffic with allow/deny rules rather than steering it through an appliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a managed, stateful firewall service that inspects and filters Layer 3-7 traffic, but it does not itself alter the IP routing table or define how packets traverse the virtual network. To force traffic to traverse an Azure Firewall for inspection, an administrator must create a user-defined route that specifies the firewall's private IP address as the next hop for the source subnet. Without such a route, packets will not automatically be sent to the firewall, making it a routing target rather than a routing mechanism.

  • ✗

    Azure Load Balancer

    Why it's wrong here

    Azure Load Balancer operates at Layer 4 to evenly distribute incoming connections across a pool of backend instances, but it does not have any role in the subnet's routing decisions. It is not a valid next-hop type in a route table, and its presence does not change the path that outbound (north-south) or lateral (east-west) traffic takes between subnets. Load balancers multiplex flows that already arrive at them, so they cannot be used to force traffic through an NVA.

  • ✗

    Network Security Groups (NSGs)

    Why it's wrong here

    Network Security Groups are stateful packet filters that permit or deny traffic based on source IP, destination IP, port, and protocol at the network interface or subnet boundary. They evaluate only packets that are already deemed routable and do not influence the routing table, the next hop, or the path a packet takes. An NSG cannot be set as a next hop and has no capability to redirect traffic, so it is purely a barrier, not a steering or forwarding mechanism.

  • ✓

    User Defined Routes (UDRs)

    Why this is correct

    User-defined routes are custom route table entries that allow you to override Azure's automatic system routes for selected subnets. By associating a route table with a subnet and setting the next hop to an NVA's private IP address, you force all matching traffic to be forwarded to that appliance for processing such as inspection or firewall enforcement. This is exactly the routing mechanism needed to steer web application traffic through a network virtual appliance, and it is the only option listed that actively changes packet forwarding behavior.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.