The canal authority is moving from a DIY hub-spoke to Virtual WAN and still needs a central inspect-and-deny point. What should the security engineer implement?
Select an answer to reveal the explanation.
Short Explanation
Virtual WAN isn’t “just another peer.” Bolt Azure Firewall onto the hub with Firewall Manager and you’ve got a secured virtual hub that can inspect and deny.
Full Explanation
A secured virtual hub is a Virtual WAN hub with Azure Firewall associated through Azure Firewall Manager, providing centralized inspection and deny controls. An NSG on a hub prefix does not create a secured virtual hub. Full-mesh branching without a firewall removes the central inspect-and-deny point. Host antivirus is not a substitute for hub network security inspection.