Branch and spoke traffic in Virtual WAN can skip the hub firewall if routing is left at defaults. What control should the security engineer set so inspection is mandatory?
Select an answer to reveal the explanation.
Short Explanation
Default Virtual WAN routing can dodge the firewall like a side canal. Set routing intent so Internet and private traffic must swim through the secured hub.
Full Explanation
Routing intent (routing policies) in Virtual WAN forces specified traffic classes—Internet and/or private—through the Azure Firewall in a secured virtual hub so branches and spokes cannot bypass inspection. Recreating the pattern with per-spoke UDRs is the classic hub-spoke approach, not the Virtual WAN control under test. Removing the firewall or sending traffic over the public Internet defeats the requirement.