Your subscription contains VNet1 with subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and a route table RT1 associated to subnet1 containing a 0.0.0.0/0 route to FW1. After deploying 10 Windows Server VMs to subnet1, none of the VM OSes activated. What should you do to allow the virtual machines to activate?
Choose an answer
Tap an option to check your answer.
Correct answer: On FW1, create an outbound network rule that allows traffic to the Azure Key Management Service (KMS)..
Why this is the answer
The correct answer is to create an outbound network rule on FW1 that allows traffic to the Azure Key Management Service (KMS). Azure VMs require access to KMS servers for activation. When a route table directs all outbound traffic (0.0.0.0/0) through a firewall, the firewall must explicitly permit this activation traffic. Without this rule, FW1 blocks the necessary communication, preventing VM activation. Deploying a NAT gateway or an Azure Standard Load Balancer with an outbound NAT rule would provide outbound internet access but wouldn't bypass the firewall's blocking of KMS traffic if no rule exists. Associating an NSG to Subnet1 allowing outbound access to port 1688 is redundant because the firewall is already controlling outbound traffic. Even if the NSG allowed it, the firewall would still block it without a specific rule.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed