Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingHard

A technician is configuring a new Azure Virtual Network (VNet) named 'VNetDev'. This VNet contains a subnet named 'AppSubnet' (10.0.1.0/24) where development application VMs will reside. The VMs in 'AppSubnet' need to access a shared file server VM in another subnet, 'FileSubnet' (10.0.2.0/24), within the same VNet. Additionally, all outbound internet traffic from 'AppSubnet' must be routed through an Azure Firewall located in 'FirewallSubnet' (10.0.0.0/24). Which combination of Azure networking features should the technician implement?

  1. AAzure Front Door for outbound internet and Service Endpoints for inter-subnet communication.
  2. BVNet peering for inter-subnet communication and Azure Firewall for outbound internet.
  3. CNetwork Security Groups (NSGs) for inter-subnet communication and Azure Firewall for outbound internet.
  4. DUser Defined Routes (UDRs) for outbound internet and NSGs for inter-subnet communication.
Show answer & explanation

Correct answer: D. User Defined Routes (UDRs) for outbound internet and NSGs for inter-subnet communication.

User Defined Routes (UDRs) are required to force all outbound internet traffic from 'AppSubnet' through the Azure Firewall. NSGs are used to control traffic flow between subnets, ensuring VMs in 'AppSubnet' can access 'FileSubnet' while still blocking unwanted traffic.

Why the other options are wrong

  • A. Azure Front Door is a global load balancer for web applications and is not used for outbound internet routing from a VNet. Service Endpoints are for accessing PaaS services, not for inter-subnet VM communication.
  • B. VNet peering connects separate VNets, not subnets within the same VNet. While Azure Firewall is correct for outbound internet, UDRs are still needed to direct traffic to it.
  • C. NSGs control traffic to/from subnets, but cannot force traffic through a firewall for internet access. Azure Firewall itself doesn't automatically route traffic.

User Defined Routes (UDRs) and Azure Firewall

UDRs allow overriding Azure's default routing to direct traffic, often used to force all outbound internet traffic from a subnet through an Azure Firewall for centralized inspection and control.

  • UDRs are applied to subnets.
  • A common use case is forced tunneling to a firewall or NVA.
  • Azure Firewall provides stateful inspection and threat intelligence.

Memory trick: UDR: 'U' Decide the Route, NSG: 'N'arrow the Security Gate.

More Implement and manage virtual networking questions