Question 1
A financial services company is designing a network architecture in Azure to host a new algorithmic trading platform. A key requirement is to ensure that traffic from the application servers in one subnet (AppSubnet) is always inspected by a Network Virtual Appliance (NVA) before reaching the database servers in another subnet (DataSubnet) within the same VNet. Which of the following is the most effective way to enforce this traffic flow without altering the VNet's address space?
Answer and explanation
Correct answer: C
The correct method to force traffic between subnets through a Network Virtual Appliance (NVA) is called service chaining, which is implemented using User-Defined Routes (UDRs). By creating a route table and associating it with the source subnet (AppSubnet), you can define a custom route for traffic destined for the target subnet (DataSubnet). Setting the next hop type to 'VirtualAppliance' and specifying the NVA's private IP address ensures that all traffic matching the route is sent to the NVA for inspection first. NSGs control access but do not redirect traffic flow. VNet peering is for connecting separate VNets, not subnets within the same VNet.