An organization is designing the routing configuration for a spoke virtual network named `vnet-spoke-prod` () in Microsoft Azure. The virtual network contains a subnet named `snet-web` ().
`vnet-spoke-prod` is peered with a hub virtual network named `vnet-hub-prod` (). The hub virtual network contains an Azure Firewall instance with the private IP address .
You have the following requirements:
- All outbound traffic from `snet-web` to the internet must be routed through the Azure Firewall for security inspection.
- All traffic from `snet-web` to an external spoke virtual network named `vnet-spoke-corp` () must be routed through the Azure Firewall.
- All internal traffic within `vnet-spoke-prod` must bypass the firewall and route directly between resources using default Azure routing.
Which two routes should you add to the route table associated with `snet-web` to meet these requirements?
- A route for with a next hop type of Virtual appliance and next hop IP address of Cevap
- A route for with a next hop type of Virtual appliance and next hop IP address of Cevap
- CA route for with a next hop type of Virtual appliance and next hop IP address of
- DA route for with a next hop type of Virtual appliance and next hop IP address of