(Same environment as an earlier question) Your subscription contains VNet Vnet1 with subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and RT1 associated to subnet1 with a 0.0.0.0/0 route to FW1. After you deploy 10 Windows Server VMs into subnet1, none of the VMs activate. What should you do to allow the VMs to activate?
Choose an answer
Tap an option to check your answer.
Correct answer: Add an internet route to RT1 specifically for the Azure Key Management Service (KMS)..
Why this is the answer
The correct answer is to add an internet route to RT1 specifically for the Azure Key Management Service (KMS). Azure VMs activate against Azure KMS servers, which are public endpoints. Since RT1 forces all 0.0.0.0/0 traffic through FW1, the VMs cannot reach the public KMS servers. Adding a specific route for the KMS service (e.g., to the internet) in RT1 bypasses FW1 for activation traffic, allowing the VMs to activate. Creating an outbound service tag rule for AzureCloud on FW1 is too broad and might not specifically address the KMS activation issue, as KMS traffic needs to bypass the firewall for activation. Configuring a DNAT rule on FW1 is for inbound traffic, not outbound activation. Deploying an Azure Standard Load Balancer with an outbound NAT rule is unnecessary; the issue is routing to a public endpoint, not providing outbound connectivity for multiple VMs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed