Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You have two Azure virtual networks named VNetA and VNetB that are connected by virtual network peering. An Azure Firewall with a private IP address of 10.0.0.4 is deployed in a dedicated subnet in VNetA. You must ensure that virtual machines in the subnet named AppSubnet in VNetB route all outbound internet traffic through the firewall. What should you configure on AppSubnet?

  • Add all virtual machines in AppSubnet to an application security group and permit traffic only from the AzureFirewall service tag.

  • Create a user-defined route with an address prefix of 0.0.0.0/0, next hop type set to Virtual appliance, and next hop IP address 10.0.0.4.

  • Create and associate a network security group on AppSubnet that denies outbound traffic to the Internet service tag.

  • Enable the Use remote gateway option on the VNet peering connection between VNetA and VNetB.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot