Your subscription contains: VNet Vnet1 with subnets subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and route table RT1 associated to subnet1 with a 0.0.0.0/0 route pointing to FW1. After you deploy 10 Windows Server VMs into subnet1, none of the VMs successfully activate (Windows activation fails). What should you do to allow the VMs to activate?
Choose an answer
Tap an option to check your answer.
Correct answer: On FW1, create an outbound network rule that allows traffic to the Azure Key Management Service (KMS)..
Why this is the answer
Windows VMs require access to a Key Management Service (KMS) for activation. By default, Azure VMs attempt to activate against an Azure KMS host. The correct solution is to create an outbound network rule on the Azure Firewall (FW1) that permits traffic to the Azure KMS. This rule should specify the KMS service endpoint or IP ranges and the required port (typically 1688). Configuring a DNAT rule for port 1688 is incorrect because DNAT is for inbound traffic translation, not outbound activation. Deploying an Application Security Group (ASG) is insufficient on its own; while ASGs can group network interfaces, the firewall still needs a rule to permit the traffic. Creating an outbound service tag rule for AzureCloud is too broad and less secure than targeting the specific KMS service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed