Question 1
A financial services company is designing a new three-tier application on Azure. The company has a strict security policy that requires all network traffic between the web, application, and data tiers to be inspected by a Network Virtual Appliance (NVA). The company also wants to centralize the management of this NVA and other shared services like DNS and Active Directory domain controllers. You need to design a network topology that meets these requirements.
Which network design should you recommend?
Answer and explanation
Correct answer: A
A hub-and-spoke topology is the recommended design for centralizing shared services and enforcing security policies. Placing the NVA and other shared services in the hub VNet allows for centralized management and inspection of all traffic. Each application tier can be isolated in its own spoke VNet, and user-defined routes (UDRs) can force all inter-spoke traffic through the NVA in the hub, meeting the inspection requirement. This design is scalable, cost-effective, and aligns with Azure best practices.