Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage VNet1, which has two subnets: Workload (10.0.1.0/24) and AzureFirewallSubnet (10.0.2.0/24). Azure Firewall (private IP 10.0.2.4) runs in AzureFirewallSubnet. All outbound traffic from Workload VMs must pass through the firewall, but traffic to Azure services that use service endpoints must remain unaffected. With minimal change and no downtime, what should you configure on the Workload subnet?
Enable forced tunneling on an Azure VPN or ExpressRoute virtual network gateway and configure 10.0.2.4 as the default route for the gateway.
Create a route table that contains a route for 0.0.0.0/0 with next hop type Virtual appliance set to 10.0.2.4, and associate the table with the Workload subnet.
Add an outbound deny rule for destination 0.0.0.0/0 to the network security group attached to the Workload subnet, then add service-endpoint rules for required services.
Create a route table that contains a route for 0.0.0.0/0 with next hop type Internet and associate the table with both subnets.
Create a route table containing a user-defined route for 0.0.0.0/0 with next hop type Virtual appliance pointing to 10.0.2.4, then associate the table with the Workload subnet. The /0 route makes Azure Firewall the default gateway for the VMs, so all internet-bound traffic is inspected. Service-endpoint traffic continues to use Azure's system routes, which are more specific and therefore take precedence, preserving platform-service connectivity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does the 0.0.0.0/0 route make Azure Firewall the default gateway?
Open an interactive chat with Bash
How do service endpoints interact with user-defined routes like 0.0.0.0/0?
Open an interactive chat with Bash
What are the advantages of using Azure Firewall as a virtual appliance?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .