select TWO - Fabrikam runs a multi-subscription environment with Azure Firewall Policy hierarchy: a global parent policy and per-hub child policies applied via Firewall Manager. They need to ensure a high-priority DENY rule for traffic from a suspicious /24 IP range is enforced across two specific hubs but allowed in others. Which TWO configurations will achieve this goal while preserving local allow rules in other hubs?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a rule collection group in the parent policy with a high priority DENY rule scoped to the two hub resource groups containing those hubs., In the parent policy, create a rule collection group with a DENY rule and use policy assignment filters to include only the two target hub virtual hubs..
Why this is the answer
The first correct option, creating a rule collection group in the parent policy with a high-priority DENY rule scoped to the two hub resource groups, works because parent policy rules are inherited by child policies. By scoping the rule to specific resource groups containing the target hubs, the DENY rule applies only where needed, while other hubs remain unaffected. The second correct option, creating a DENY rule in the parent policy and using policy assignment filters to include only the two target virtual hubs, achieves the same outcome. Policy assignment filters allow granular control over where a parent policy's rules are applied, ensuring the DENY rule targets only the specified hubs. The incorrect options either misapply inheritance, override mechanisms, or would affect all child policies universally. Adding a DENY rule to each child policy would be less efficient and harder to manage centrally.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed