Every hub firewall must share a baseline (deny Internet RDP, threat intel on) while each region adds its own FQDNs. What should the security engineer use?
Select an answer to reveal the explanation.
Short Explanation
One parent Firewall Policy for the shared baseline, child policies for regional FQDNs, steered by Firewall Manager. Stop Xeroxing classic rules onto every hub.
Full Explanation
Azure Firewall Manager with Firewall Policy supports a parent/child hierarchy so shared baselines (deny Internet RDP, threat intelligence) inherit while regions add FQDN or other rule collections. Classic per-firewall rule copy-paste drifts and is not the current policy model. Azure Policy initiatives govern Azure resource compliance and are not a substitute for Firewall Policy. NSGs do not replace centralized firewall policy management.