Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company is migrating its on-premises virtual machines to Azure. They need to ensure that the virtual machines in Azure can communicate with their on-premises network securely over the internet, using an encrypted tunnel. Which Azure service should they use?

  1. AAzure Virtual Network
  2. BAzure ExpressRoute
  3. CAzure Firewall
  4. DAzure VPN Gateway
Show answer & explanation

Correct answer: D. Azure VPN Gateway

Azure VPN Gateway allows you to create a secure, encrypted connection (VPN tunnel) over the public internet between your on-premises network and an Azure Virtual Network. This enables resources in Azure to communicate securely with on-premises resources.

Why the other options are wrong

  • A. Azure Virtual Network provides network isolation and connectivity for Azure resources but doesn't create the secure tunnel to on-premises itself.
  • B. Azure ExpressRoute provides a private, dedicated connection, not over the public internet.
  • C. Azure Firewall provides network security and threat protection but doesn't establish encrypted tunnels to on-premises networks.

Azure VPN Gateway

A service that creates encrypted cross-premises connections between an Azure Virtual Network and on-premises locations over the public internet.

  • Establishes secure VPN tunnels over the internet
  • Connects Azure VNets to on-premises networks
  • Supports Site-to-Site and Point-to-Site VPNs
  • Used for hybrid cloud connectivity

Memory trick: VPN Gateway: Your secure internet bridge to Azure.

More Describe Azure identity, security, and networking questions