CASE STUDY: Contoso Ltd is a global financial services company migrating to Azure.
Current environment: 3 on-premises datacenters (New York, London, Tokyo) connected via MPLS.
Azure footprint: 1 Hub VNet in East US, 1 Hub in UK South. 50 Spoke VNets peered to the Hubs.
Requirements:
QUESTION: To meet Requirement 2 (Inspect all internet-bound traffic from spokes), you deploy Azure Firewall in the Hub VNets. How must you configure the Spoke VNets to ensure traffic is routed to the firewall?
AZ-305 · Question 53 · Domain 4.4: Network Solutions
CASE STUDY: Contoso Ltd is a global financial services company migrating to Azure.
Current environment: 3 on-premises datacenters (New York, London, Tokyo) connected via MPLS.
Azure footprint: 1 Hub VNet in East US, 1 Hub in UK South. 50 Spoke VNets peered to the Hubs.
Requirements:
QUESTION: To enhance Requirement 2, the security team now requires that the Azure Firewall inspects the payload of outbound HTTPS traffic to block malicious file downloads. Which Firewall SKU and feature must you use?
Answer options:
Azure Firewall Standard with Threat Intelligence
Azure Firewall Premium with TLS Inspection
Azure Web Application Firewall (WAF)
Network Security Groups (NSGs) with Application Security Groups (ASGs)
55 questions · hints · full answers · grading