Microsoft Azure Security Engineer Associate AZ-500 Practice Question
An NVA at 10.0.0.4 in GatewaySubnet must inspect all Internet-bound traffic from AppSubnet (10.0.2.0/24). AppSubnet's virtual network is peered with another VNet that uses 10.1.0.0/16; peering traffic must bypass the NVA. You apply a UDR to AppSubnet. How should you configure the route?
Add a route with address prefix 0.0.0.0/0 and next hop type Internet.
Add two routes: 0.0.0.0/0 to Virtual appliance 10.0.0.4 and 10.1.0.0/16 to next hop None.
Add a route with address prefix 0.0.0.0/0 and next hop type Virtual appliance set to 10.0.0.4.
Add two routes: 0.0.0.0/0 to Virtual appliance 10.0.0.4 and 10.1.0.0/16 to next hop Virtual network.
To force only Internet-destined traffic through the NVA, create one UDR with address prefix 0.0.0.0/0 and next hop type Virtual appliance pointing to 10.0.0.4. The system route for 10.1.0.0/16 created by VNet peering has a longer prefix than 0.0.0.0/0, so it remains in effect and continues to send traffic directly between the peer networks. Adding an explicit 10.1.0.0/16 UDR is unnecessary; setting its next hop to None would black-hole that traffic, and setting its next hop to Virtual network would be ignored because system routes already handle the prefix. Using next hop Internet on 0.0.0.0/0 would bypass the NVA entirely.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a UDR in Azure?
Open an interactive chat with Bash
What is an NVA in Azure?
Open an interactive chat with Bash
What is VNet peering in Azure?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .