An enterprise plans to connect 80 branch offices using SD-WAN appliances to Azure and provide local internet breakout through a managed security stack in Azure. They also want to connect multiple VNets to the same hubs and steer branch-to-internet and branch-to-VNet traffic through Azure Firewall with central control. Which Virtual WAN design meets the requirements with least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy Virtual WAN Standard hubs in two regions, attach branch VPN sites via partner automation, connect VNets to the hubs, and enable routing intent to send internet and private traffic to Azure Firewall..
Why this is the answer
This option is correct because Azure Virtual WAN Standard hubs support routing intent, which centralizes traffic steering to Azure Firewall for both internet and private (branch-to-VNet) traffic, meeting the requirement for central control and managed security. Deploying in two regions provides redundancy. Partner automation simplifies connecting 80 branch offices. Virtual WAN Basic hubs do not support routing intent, making them unsuitable. A traditional hub VNet with a VPN Gateway lacks the scalability and centralized routing features of Virtual WAN, increasing operational overhead. Placing Azure Firewall in a spoke VNet with Virtual WAN Standard hubs prevents routing intent from steering internet traffic to it. Routing intent is a feature of Virtual WAN Standard, not Basic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed