Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You deploy an Azure SQL Managed Instance named prod-mi to the ProdData subnet of a virtual network that uses the address space 10.20.0.0/16.
The networking team will implement forced tunneling so that all outbound traffic from ProdData is sent to the on-premises firewall across an existing site-to-site VPN. They plan to associate the following user-defined route (UDR) with the ProdData subnet:
Destination prefix: 0.0.0.0/0 Next hop type: Virtual network gateway
You must ensure that:
prod-mi continues to receive required platform management and patching traffic from Azure.
All other outbound Internet traffic from the subnet continues to be forced through the on-premises firewall.
Which change should you recommend?
Create an outbound NSG rule that permits TCP 443 to the AzureCloud service tag and give it the highest priority.
Enable a setting named AllowOutboundOnlyInternetTraffic on prod-mi.
Move prod-mi to a newly delegated subnet because forced tunneling is unsupported on delegated subnets.
Add a user-defined route to ProdData with destination SqlManagement (Service Tag) and next hop type Internet.
Azure SQL Managed Instance receives control-plane traffic (automatic patching, failover commands, and other management operations) over public endpoints represented by the SqlManagement service tag. If a 0.0.0.0/0 UDR is applied without exception, that traffic is redirected to the VPN gateway and the instance will become unhealthy. Add a more-specific UDR that targets the SqlManagement tag and points to the Internet. Because Azure routing uses longest-prefix match, the SqlManagement route overrides the broader 0.0.0.0/0 route, allowing only the required management traffic to bypass forced tunneling while all other destinations continue to follow the default route to the on-premises firewall.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Service Tag in Azure?
Open an interactive chat with Bash
Why does forced tunneling impact Azure SQL Managed Instances?
Open an interactive chat with Bash
How does Azure routing prioritize User-Defined Routes (UDRs)?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .