VNet1 hosts an Azure Virtual Desktop host pool named Pool1. You need to ensure all outbound traffic from Pool1 passes through Azure Firewall and that TLS inspection is applied. Which two resources must you configure? (Each correct answer is one point.)
Choose an answer
Tap an option to check your answer.
Correct answer: an Azure key vault, a managed identity.
Why this is the answer
To apply TLS inspection with Azure Firewall, you need to decrypt and re-encrypt TLS traffic. Azure Firewall Premium uses a private key for decryption and a public key for re-encryption. This private key must be stored securely in an Azure Key Vault. The Azure Firewall then needs permission to access this Key Vault to retrieve the private key. This access is granted through a managed identity assigned to the Azure Firewall, which authenticates to the Key Vault. An Azure Private DNS zone is used for name resolution within a VNet, not for TLS inspection. A private endpoint provides private connectivity to Azure services, which is unrelated to TLS inspection. An Azure NAT gateway provides outbound internet connectivity and IP address translation, not TLS inspection. A Microsoft Entra enterprise app and a managed identity are both related to identity, but only a managed identity is used by Azure Firewall for Key Vault access in this scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed