Orion Retail is evaluating two deployment models using Azure Firewall Manager: 'secured virtual hub' (SVH) with Azure Virtual WAN Hub and the traditional 'hub VNet' model with a VNet-based firewall. They need centralized policy, automated spoke onboarding, and native hub-to-hub transitive routing. Which statement correctly contrasts the secured virtual hub with the hub VNet model?
Choose an answer
Tap an option to check your answer.
Correct answer: Secured virtual hub provides a managed, scale-out firewall in a Virtual WAN hub with built-in transitive routing and automated spoke connections; hub VNet model uses a single VNet with a manually managed firewall instance and requires user-configured spoke peering for transitive routing..
Why this is the answer
The secured virtual hub (SVH) model, leveraging Azure Virtual WAN, offers a fully managed, scalable Azure Firewall instance integrated directly into the Virtual WAN hub. This provides automated transitive routing between spokes and other hubs, and simplifies spoke onboarding. The hub VNet model, in contrast, uses a standard VNet where an Azure Firewall instance is manually deployed and managed. Transitive routing between spokes or hubs in this model typically requires user-configured VNet peering or UDRs. The SVH supports all Azure Firewall tiers, including Premium. Both models integrate with Azure Firewall Manager for centralized policy management. SVH provides native high availability and scalability without requiring additional NVAs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed