RetailCo runs a hub-spoke design using a Secured Virtual Hub with Azure Firewall. They want all internet-bound traffic from spokes to be inspected centrally. Which hub route table configuration will ensure centralized egress and avoid hairpinning or bypass from the spokes?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a hub route table with a 0.0.0.0/0 static route whose next hop is the Azure Firewall private IP, set the routing intent so Internet traffic is inspected by the secured hub, and associate the route table with each spoke connection..
Why this is the answer
This option correctly leverages Azure Virtual WAN's capabilities for centralized internet egress. By creating a hub route table with a 0.0.0.0/0 route pointing to the Azure Firewall's private IP and setting routing intent for internet traffic inspection, all internet-bound traffic from associated spokes will be directed through the Firewall in the secured hub. Associating this route table with each spoke connection ensures consistent policy enforcement and prevents spokes from bypassing the firewall, avoiding hairpinning. The other options are incorrect: Creating UDRs on every spoke subnet and configuring the Firewall in transparent mode is not the recommended or most efficient approach for Virtual WAN and Secured Virtual Hubs. Transparent mode is not a standard Azure Firewall configuration for this scenario. Installing Azure Route Server in each spoke is an overly complex and unnecessary solution for this requirement when Virtual WAN's routing capabilities are designed for it. Enabling Forced tunneling on VPN gateways is typically for on-premises connectivity and would not directly route all VNet internet traffic through the Azure Firewall in the hub in this manner.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed