Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your virtual network has a Spoke-App subnet with a route table that contains one user-defined route (0.0.0.0/0 → virtual appliance 10.10.100.4). Virtual network gateway route propagation is disabled on the table. A site-to-site VPN gateway advertises 172.16.0.0/16 to Azure by BGP. After the route table is applied, Spoke-App can no longer reach 172.16.0.0/16. You must restore that connectivity without changing the default egress through the firewall. What should you do?
Enable virtual network gateway route propagation for the route table.
Add a route for 172.16.0.0/16 with next hop type Virtual appliance and next hop IP 10.10.100.4.
Remove the 0.0.0.0/0 route and rely on system routes.
Change the next hop type of the 0.0.0.0/0 route to Virtual network gateway.
Because virtual network gateway route propagation is disabled, the BGP-learned prefix 172.16.0.0/16 is not added to the subnet's effective routes. The only matching entry is the user-defined default route, so traffic is sent to the firewall and then dropped. Re-enabling gateway route propagation adds the more specific 172.16.0.0/16 route (next hop Virtual network gateway). Longest-prefix match then directs traffic for 172.16.0.0/16 through the VPN gateway, while all other traffic continues to follow the 0.0.0.0/0 default route through the firewall. The other options either still forward the on-premises traffic to the firewall or remove the desired forced-tunnelling behaviour.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'virtual network gateway route propagation' mean in Azure?
Open an interactive chat with Bash
What is the 'longest-prefix match' routing principle in networking?
Open an interactive chat with Bash
What is a virtual appliance in Azure networking?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .