Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard

A company is migrating its on-premises applications to Azure. They require a dedicated, private, and high-bandwidth connection from their datacenter to their Azure Virtual Networks, bypassing the public internet for enhanced security and reliability. Which Azure networking service should they choose?

  1. AAzure Peering Service
  2. BAzure VPN Gateway
  3. CAzure Virtual WAN
  4. DAzure ExpressRoute
Show answer & explanation

Correct answer: D. Azure ExpressRoute

Azure ExpressRoute creates a private connection between your on-premises network and Azure, bypassing the public internet. It offers higher bandwidth, lower latency, and increased reliability compared to typical internet-based VPN connections, making it ideal for hybrid cloud scenarios requiring dedicated connectivity.

Why the other options are wrong

  • A. Azure Peering Service optimizes internet routing to Azure services, but doesn't provide a dedicated private connection from on-premises.
  • B. Azure VPN Gateway establishes encrypted connections over the public internet, which doesn't meet the 'bypassing the public internet' requirement.
  • C. Azure Virtual WAN is a networking service that brings many networking, security, and routing functionalities together, but relies on ExpressRoute or VPN for connectivity.

Azure ExpressRoute

A service that creates private connections between Azure data centers and infrastructure on-premises or in a colocation environment.

  • Bypasses the public internet, offering enhanced security and reliability.
  • Provides higher bandwidth and lower latency than VPNs.
  • Ideal for hybrid cloud, large-scale data transfers, and business-critical workloads.

Memory trick: ExpressRoute is the express lane to Azure, no public detours.

More Describe Azure identity, security, and networking questions