For outbound traffic originating from VNet1 you must: perform transparent proxying to external web servers, inspect all outbound TLS, and minimize cost. Which resource should you include?
Choose an answer
Tap an option to check your answer.
Correct answer: FW1.
Why this is the answer
FW1, an Azure Firewall Premium instance, is the correct choice because it supports transparent proxying for outbound traffic and TLS inspection, both explicitly required. Azure Firewall Premium offers advanced threat protection capabilities, including IDPS and URL filtering, which are essential for inspecting all outbound TLS traffic. While FW2 is also an Azure Firewall, it's a Standard SKU which lacks TLS inspection and transparent proxy features. AG1 (Azure Application Gateway) is a Layer 7 load balancer and WAF, primarily for inbound traffic, not outbound transparent proxying or general TLS inspection of arbitrary external web servers. FD1 (Azure Front Door) is a global load balancer and CDN, also primarily for inbound traffic and acceleration, not for outbound transparent proxying or TLS inspection from a VNet.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed