AeroParts wants to deploy Azure Firewall in a Secured Virtual Hub using Azure Firewall Manager so the security team can manage policies centrally. What is the correct deployment approach to use Azure Firewall Manager for a secured virtual hub?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Azure Firewall Manager to create a Secured Virtual Hub resource and deploy Azure Firewall (Standard or Premium) via the Firewall Manager flow; associate a Firewall Policy and create the hub through the Firewall Manager blade..
Why this is the answer
The correct approach leverages Azure Firewall Manager's integrated workflow for secured virtual hubs. Firewall Manager is designed to centralize management and deployment. By using Firewall Manager to create the secured virtual hub and deploy the Azure Firewall (Standard or Premium) directly, you ensure proper integration and policy management from the outset. This method streamlines the process and ensures all components are configured correctly for central policy enforcement. Manually deploying an Azure Firewall via an ARM template and then importing it is less efficient and doesn't fully utilize Firewall Manager's capabilities for hub creation. Deploying a VM-Series firewall from the Marketplace is for third-party firewalls, not Azure Firewall itself. Deploying Azure Firewall in each spoke's subnet is incorrect for a hub-and-spoke model with a central secured virtual hub; the firewall should be in the hub.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed