A company deploys Virtual WAN with multiple hubs and needs to isolate spoke VNets so they can only communicate with on-premises, not with other spokes. Which feature enables this isolation?
-
A
Network security groups on spoke VNets
-
B
Custom route tables with propagation control
-
C
Azure Firewall DNAT rules
-
D
Hub peering policies