HOTSPOT You have an Azure subscription that contains the Azure Firewall policies shown in the following table. 


Does anyone else think the first is a bit tricky because of the network vs application rule detail? Seems like "No" is right for URL filtering on VNet1 since that's only for application rules, not network ones. The encrypted inspection one is a trap too, peering alone isn't enough.
No, Yes, No for these. First one is a no because URL filtering only applies to application rules, not network rules in Azure Firewall (even if it's Premium tier). Second is yes since the Premium firewall on VNet2 includes IDPS. Third one is no, peering alone doesn't route traffic through the firewall for encrypted inspection. Pretty sure that's right but open to other views.
