Microsoft Azure Security Engineer Associate AZ-500 Practice Question

An Azure virtual network is connected to an on-premises datacenter through a VPN gateway that advertises the 0.0.0.0/0 default route to the virtual network by using BGP. After the change, virtual machines in the AppSubnet send all outbound internet traffic through the on-premises network, but they must regain direct internet access while continuing to reach the on-premises prefixes through the VPN gateway. Which configuration should you apply to AppSubnet?

  • Disable virtual network gateway route propagation on AppSubnet's route table.

  • Associate a route table to AppSubnet that contains a 0.0.0.0/0 route with next hop type Internet.

  • Deploy Azure Firewall in the virtual network and add a 0.0.0.0/0 route that points to the firewall's private IP.

  • Associate a route table to AppSubnet that contains a 0.0.0.0/0 route with next hop type None.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot