AZ-500 · Question #46
Drag and Drop Question You have an Azure subscription that contains the virtual networks shown in the following table. The Azure virtual machines on SpokeVNetSubnet0 can communicate with the…
The correct answer is GatewaySubnet; HubVNetSubnet0. RT1 should be associated with GatewaySubnet so that traffic arriving from the on-premises network via the VPN/ExpressRoute gateway is redirected to the Azure Firewall's private IP before reaching SpokeVNetSubnet0. RT2 should be associated with HubVNetSubnet0 (or…
Question
Exhibits
Answer Area
Drag items
Correct arrangement
- GatewaySubnet
- HubVNetSubnet0
Explanation
RT1 should be associated with GatewaySubnet so that traffic arriving from the on-premises network via the VPN/ExpressRoute gateway is redirected to the Azure Firewall's private IP before reaching SpokeVNetSubnet0. RT2 should be associated with HubVNetSubnet0 (or SpokeVNetSubnet0 peered subnet) to force traffic originating from the spoke network toward the on-premises network through the Azure Firewall as the default gateway, with BGP propagation disabled to prevent the learned on-premises routes from bypassing the firewall. This bidirectional routing through the firewall ensures all traffic between SpokeVNetSubnet0 and the on-premises network is inspected.
Topics
Community Discussion
No community discussion yet for this question.

