Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company wants to establish a secure, private connection between their on-premises network and their Azure Virtual Network. They require high bandwidth and consistent low latency, and the connection must not traverse the public internet. Which Azure networking service should they use?

  1. AAzure Application Gateway
  2. BAzure VPN Gateway
  3. CAzure Load Balancer
  4. DAzure ExpressRoute
Show answer & explanation

Correct answer: D. Azure ExpressRoute

Azure ExpressRoute provides a private, dedicated connection between on-premises networks and Azure, offering higher bandwidth, lower latency, and greater reliability than typical internet-based connections.

Why the other options are wrong

  • A. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications, not for private site-to-site connectivity.
  • B. Azure VPN Gateway creates encrypted tunnels over the public internet, which doesn't meet the 'not traverse the public internet' requirement.
  • C. Azure Load Balancer distributes incoming network traffic across backend resources, not for private connectivity between on-premises and Azure.

Azure ExpressRoute

A service that provides a private, dedicated connection between on-premises networks and Azure datacenters.

  • Does not traverse the public internet.
  • Offers higher bandwidth and lower latency.
  • Provides more reliable connectivity than internet-based VPNs.

Memory trick: ExpressRoute is the 'direct highway' from 'on-prem' to 'Azure'.

More Describe Azure identity, security, and networking questions