Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureEasy
A global manufacturing company is designing a new Azure environment to host its critical production control systems. These systems require extremely low latency, high bandwidth, and a direct, private connection to on-premises operational technology (OT) networks. Security demands isolation from the public internet and other Azure workloads. Which Azure networking service should the architect recommend to meet these requirements?
- AAzure Virtual Network Gateway with Site-to-Site VPN
- BAzure ExpressRoute
- CAzure VPN Gateway with Point-to-Site VPN
- DAzure Virtual WAN
Show answer & explanationAnswer & explanation
Correct answer: B. Azure ExpressRoute
Azure ExpressRoute provides a private, dedicated, and high-bandwidth connection between on-premises networks and Azure, bypassing the public internet. This directly addresses the requirements for low latency, high bandwidth, and isolation for critical production control systems.
Why the other options are wrong
- A. Site-to-Site VPN uses the public internet, which does not meet the isolation and performance requirements.
- C. Point-to-Site VPN is for individual client connections, not for connecting entire on-premises networks.
- D. Azure Virtual WAN simplifies large-scale branch connectivity but ExpressRoute is the underlying private link technology for the dedicated connection.
Azure ExpressRoute
A service that creates private connections between Azure data centers and on-premises infrastructure or a colocation environment.
- Bypasses the public internet, offering enhanced security.
- Provides higher bandwidth and lower latency than VPNs.
- Ideal for hybrid cloud scenarios with critical workloads.
Memory trick: ExpressRoute is like a private highway, not a public road.