A municipality has many branches, many regions, and a requirement for a managed any-to-any hub with integrated firewall. What architecture should the security engineer recommend?
Select an answer to reveal the explanation.
Short Explanation
Too many branches and regions for a DIY peering quilt. Grab Virtual WAN with a secured virtual hub and let the managed any-to-any fabric carry the firewall.
Full Explanation
Virtual WAN with a secured virtual hub provides a managed any-to-any connectivity fabric and integrated Azure Firewall, which fits multi-branch, multi-region designs better than manually recreating peering, gateway transit, and UDRs everywhere. Full-mesh peering without a firewall fails the integrated inspection requirement. Classic hub-spoke remains valid for smaller estates but is not the best fit when the scenario asks for the managed Virtual WAN secured-hub model.