Does Azure Firewall Mark a Virtual WAN Hub as Secured?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1. Hub1 has a security status of Unsecured. You need to ensure that the security status of Hub1 is marked as Secured. Solution: You implement Azure Firewall. Does this meet the requirement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that a hub's Secured status is a property of the Virtual WAN hub itself and comes only from an in-hub Azure Firewall, not from NSGs or spoke-level filtering.
A Virtual WAN hub shows a security status of Unsecured until an Azure Firewall is deployed into the hub and managed through Azure Firewall Manager, which converts it into a secured virtual hub. This page confirms that implementing Azure Firewall for Hub1 in VWAN1 does meet the requirement to mark Hub1 as Secured.
Answering No (B) under the belief that NSGs, UDRs, or a firewall deployed in a spoke VNet are enough — those filter traffic but leave Hub1's security status as Unsecured.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Yes. The requirement is about the hub security status field of Hub1 in VWAN1, which changes from Unsecured to Secured only when the hub is turned into a secured virtual hub. Microsoft defines a secured virtual hub as an Azure Virtual WAN hub that has Azure Firewall deployed into it together with associated security and routing policies configured through Azure Firewall Manager. Because the solution implements Azure Firewall for Hub1, the firewall is placed in the hub itself, and the hub is therefore reported as Secured. The scenario asks only whether the requirement is met, and deploying Azure Firewall is exactly the documented method for achieving it. Routing intent and inter-hub traffic inspection are side benefits of the same design, not prerequisites for the status change.Why the Other Options Are Wrong
"No" is the only alternative and it is wrong because Azure Firewall is precisely the mechanism Microsoft documents for securing a Virtual WAN hub. NSGs, which one community member floated, are layer-4 subnet-level controls attached to subnets or NICs; they cannot be attached to a hub and never alter the hub's security status. A firewall or NVA placed in a spoke VNet may inspect east-west traffic, but Hub1 itself remains Unsecured because there is no security provider inside the hub. Likewise, hub-to-hub connectivity or custom routing without an in-hub firewall leaves the status unchanged, so nothing in option B can be justified.Community Comment Notes
Osax supplies the decisive documentation definition — a secured virtual hub is "an Azure Virtual WAN Hub with associated security and routing policies configured by Azure Firewall Manager" — which maps one-to-one onto this solution. evangelist simply confirms it with "correct answer", matching the vote record. bobothewiseman's note to "Implement NSG or Firewall" captures the common half-truth: the firewall part is right, but the NSG part reflects a misunderstanding, since NSGs play no role in the Secured status of a Virtual WAN hub.Official Reference
Exam Strategy
For Virtual WAN 'Does this meet the requirement?' items, isolate the exact noun being changed — here the hub's security status, not traffic filtering. If the solution puts an Azure Firewall (or Firewall Manager-managed NVA) inside the hub, the status becomes Secured and the answer is Yes; if the solution only touches spokes, subnets, or NSGs, answer No.
Frequently Asked Questions
Why doesn't an NSG secure a Virtual WAN hub such as Hub1?
NSGs attach to subnets and NICs to filter layer-4 traffic; they cannot be attached to a Virtual WAN hub, so they never change Hub1's Unsecured status.
Must the Azure Firewall be deployed inside Hub1 itself?
Yes. Only an in-hub Azure Firewall managed by Azure Firewall Manager (or an equivalent managed NVA) converts Hub1 to a secured virtual hub; a spoke firewall leaves the status Unsecured.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →