Microsoft Azure Security Engineer Associate AZ-500 Practice Question
HubVNet in subscription A contains both a VPN gateway and an Azure Firewall. You peer HubVNet with SpokeVNet in subscription B. SpokeVNet must send all on-premises traffic through the VPN gateway in HubVNet so that it is inspected by the Azure Firewall before reaching any resources. Which peering configuration should you use to meet this requirement?
Disable gateway transit on both sides and rely solely on user-defined routes in SpokeVNet.
Enable Allow gateway transit on both sides of the peering.
Enable Use remote gateway on both sides of the peering.
On the HubVNet-to-SpokeVNet peering, enable Allow gateway transit; on the SpokeVNet-to-HubVNet peering, enable Use remote gateway.
Gateway transit allows a peered virtual network that owns a VPN gateway (the hub) to share that gateway with another peered virtual network (the spoke). To enable this, the hub side of the peering must be set to "Allow gateway transit", and the spoke side must be set to "Use remote gateway". Enabling the settings in any other combination either prevents the spoke from using the hub gateway or produces a configuration that Azure will not allow.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Can you explain 'Allow Gateway Transit' and why it's necessary here?
Open an interactive chat with Bash
What is 'Use Remote Gateway' and why is it set on the spoke side?
Open an interactive chat with Bash
How does Azure Firewall inspect traffic between VNet peers?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .