Free Microsoft Azure AZ-700 Actual Exam Questions - Question 2 Discussion
the series contains a unique solution that might meet the stated goals- Some question sets might
have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have on Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains
a hub named Hub1.
Hub! has a security status of Unsecured.
You need to ensure that the security status of Hub1 is marked as Secured.
Solution: You implement Azure NAT Gateway.
Does this meet the requirement?
Option B makes the most sense here. NAT Gateway is mostly about managing outbound connections and doesn’t provide the kind of threat protection or traffic inspection needed to change Hub1’s security status to Secured. The question hints that securing the hub usually involves deploying a firewall or similar security appliance, which NAT Gateway doesn’t do. So just adding NAT Gateway isn’t enough to meet the requirement.
B imo, NAT Gateway mainly deals with outbound connectivity and doesn’t impact the security status of the hub. The “Secured” status typically requires a firewall like Azure Firewall or a security appliance integrated into the hub to inspect and control traffic. Just adding NAT Gateway won’t change that flag.
B, since NAT Gateway doesn’t provide the security features needed to secure the hub.
B NAT Gateway is more about managing outbound traffic, not about securing the hub itself. To change the status to Secured, you’d need something like Azure Firewall or other security appliances in the hub.
B NAT Gateway won’t affect Virtual WAN hub’s security status directly.
It’s B. NAT Gateway mainly handles outbound traffic, not the overall security posture of the Virtual WAN hub, so it won’t switch the status to Secured.
Option B seems right here. Just adding a NAT Gateway doesn’t really change the security status of the hub itself-it’s more about outbound internet traffic. Would like to see a proper explanation on this though.