Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your virtual network has a Spoke-App subnet with a route table that contains one user-defined route (0.0.0.0/0 → virtual appliance 10.10.100.4). Virtual network gateway route propagation is disabled on the table. A site-to-site VPN gateway advertises 172.16.0.0/16 to Azure by BGP. After the route table is applied, Spoke-App can no longer reach 172.16.0.0/16. You must restore that connectivity without changing the default egress through the firewall. What should you do?

  • Enable virtual network gateway route propagation for the route table.

  • Add a route for 172.16.0.0/16 with next hop type Virtual appliance and next hop IP 10.10.100.4.

  • Remove the 0.0.0.0/0 route and rely on system routes.

  • Change the next hop type of the 0.0.0.0/0 route to Virtual network gateway.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot