Your subscription contains Vnet1 with subnets Subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and a route table RT1 associated to Subnet1 that routes 0.0.0.0/0 to FW1. After you deploy 10 Windows Server VMs to Subnet1, none of the VMs activated. What change will allow the VMs to complete Windows activation?
Choose an answer
Tap an option to check your answer.
Correct answer: Add an internet route to RT1 for the Azure Key Management Service (KMS)..
Why this is the answer
The correct answer is to add an internet route to RT1 for the Azure Key Management Service (KMS). Windows activation requires outbound access to KMS servers, typically on port 1688. Since RT1 forces all 0.0.0.0/0 traffic through FW1, the firewall must explicitly allow this traffic. Adding a specific route for KMS traffic to the internet in RT1 bypasses FW1 for activation, allowing the VMs to reach the necessary KMS endpoints directly. Configuring a DNAT rule on FW1 is incorrect because DNAT is for inbound traffic translation, not outbound. Deploying a NAT gateway is unnecessary as the VMs already have outbound connectivity through FW1 (though it's currently blocked). Associating an NSG to Subnet1 allowing outbound port 1688 is insufficient because the route table (RT1) still directs all traffic through FW1, which would block it unless FW1 itself has a rule allowing it, or the traffic bypasses FW1.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed