Fabrikam runs a Secured Virtual Hub in Central US with Azure Firewall. They want all private spoke-to-spoke traffic to route normally between spokes, but require all internet-bound traffic from spokes to be inspected by the hub Azure Firewall before egress. Which Virtual WAN configuration achieves this?
Choose an answer
Tap an option to check your answer.
Correct answer: On the secured virtual hub, set routing intent so that Internet traffic is directed to the Azure Firewall and create a hub route table with a 0.0.0.0/0 static route next-hop pointing to the Firewall private IP; associate that route table to the spoke connections..
Why this is the answer
The correct configuration leverages Azure Virtual WAN's routing intent feature, which simplifies directing internet-bound traffic to a security appliance like Azure Firewall within a secured hub. By setting the routing intent for internet traffic to the Azure Firewall, and then creating a hub route table with a 0.0.0.0/0 static route pointing to the Firewall's private IP, all internet-bound traffic from associated spokes will be forced through the firewall for inspection. Associating this route table to the spoke connections ensures the policy applies to them. Incorrect options: NSGs are stateless firewalls and cannot forward traffic; they filter based on rules. IP forwarding on firewall NICs is irrelevant here. A UDR with 'Internet' next hop would send traffic directly to the internet, bypassing the firewall. Forced tunneling is for on-premises traffic. ExpressRoute Global Reach connects ExpressRoute circuits, not for directing internet traffic through a firewall. Route filtering is not the mechanism for this.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed