SC-100 Practice Question 3951

Exam: SC-100
Domain: Design security solutions for infrastructure
Difficulty: medium
You need to design a zero-trust network perimeter for an enterprise Hub-and-Spoke topology in Azure. All egress and spoke-to-spoke traffic must undergo stateful packet inspection and threat intelligence filtering. What should you place in the Hub VNet?

Answer Options

A
Azure Firewall Premium with TLS inspection and IDPS
B
A basic Network Security Group on the gateway subnet
C
An internal Layer 4 Azure Load Balancer
D
Direct VNet peering without routing appliances

Correct Answer

A: Azure Firewall Premium with TLS inspection and IDPS

Explanation

Azure Firewall Premium deployed in the central Hub virtual network provides stateful traffic inspection, TLS inspection, IDPS (Intrusion Detection and Prevention), and URL filtering.