Azure Routing Flashcards
7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Azure Routing flashcards as text
You need all internet-bound traffic from Azure VMs to route through an on-premises firewall. Which configuration implements forced tunneling?
Answer: Configure a UDR with 0.0.0.0/0 pointing to the VPN or ExpressRoute gateway as next hop
Forced tunneling is implemented by creating a UDR for 0.0.0.0/0 with next hop VirtualNetworkGateway, which overrides the default internet route and sends all traffic through the VPN or ExpressRoute connection back to on-premises.
In a hub-spoke topology where spoke VNets are peered to the hub, which configuration is required to route traffic between spoke VNets through an NVA in the hub?
Answer: Create UDRs in each spoke subnet with routes for other spokes' prefixes pointing to the NVA private IP
VNet peering is non-transitive, so UDRs must be created in each spoke's subnets directing inter-spoke traffic to the hub NVA's private IP address.
What does a 'black hole' route mean in the context of Azure networking?
Answer: A route with next hop type 'None' that silently drops matching traffic
A black hole route uses the 'None' next hop type, causing Azure to silently discard all traffic matching that destination prefix without sending an ICMP unreachable message.
Which Azure Virtual WAN component is responsible for managing route propagation and aggregation between connected branches, VNets, and hubs?
Answer: Virtual Hub Router
The Virtual Hub Router is the built-in routing engine within each Azure Virtual WAN hub that manages route tables, propagation, and association for all connected resources.
When two VNets are connected via VNet peering with 'Allow Gateway Transit' enabled on the hub and 'Use Remote Gateways' on the spoke, what happens to the spoke VNet's routing?
Answer: The spoke VNet's subnets learn routes from the hub's connected gateways automatically
With 'Allow Gateway Transit' on the hub peering and 'Use Remote Gateways' on the spoke peering, the spoke subnets automatically receive routes from the hub's VPN or ExpressRoute gateway.
Which tool in the Azure portal allows you to trace the next hop for traffic from a specific VM to a destination IP address for routing troubleshooting?
Answer: Network Watcher – Next Hop
Network Watcher's 'Next Hop' feature evaluates the effective routing for a VM's NIC and returns the next hop type and IP for a specified destination, directly reflecting the VM's effective route table.
You have a route table with a UDR for 10.1.0.0/16 pointing to an NVA. The NVA also resides in the same subnet. What routing issue can occur?
Answer: The NVA will drop all traffic due to IP forwarding being disabled by default
By default, Azure drops traffic forwarded to a VM because IP forwarding is disabled on the NIC; you must explicitly enable IP forwarding on the NVA's network interface for it to forward packets.