Given multiple virtual networks and Azure Firewall deployed to VNet3, you must force traffic from Subnet1-1 to Subnet2-1 to traverse the firewall. Which configuration accomplishes that?
Choose an answer
Tap an option to check your answer.
Correct answer: a route table associated to Subnet1-1 and Subnet2-1.
Why this is the answer
To force traffic from Subnet1-1 to Subnet2-1 through Azure Firewall in VNet3, you need a User-Defined Route (UDR). A route table associated with Subnet1-1 must contain a route for Subnet2-1 with a next hop type of "Virtual Appliance" and the IP address of the Azure Firewall. Similarly, a route table associated with Subnet2-1 must contain a route for Subnet1-1 with the Azure Firewall as the next hop. This ensures that traffic between these subnets is explicitly directed through the firewall for inspection. Peering links between VNet1 and VNet2 alone only enable connectivity, not forced tunneling through a firewall. An Azure Private DNS zone resolves names but doesn't control traffic flow. A route table associated with AzureFirewallSubnet is for traffic leaving the firewall, not for directing traffic to it from other subnets.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed