Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
A company is migrating its on-premises virtual machines to Azure. They need to ensure that the virtual machines in Azure can communicate with their on-premises network securely over the internet, using an encrypted tunnel. Which Azure service should they use?
- AAzure Virtual Network
- BAzure ExpressRoute
- CAzure Firewall
- DAzure VPN Gateway
Show answer & explanationAnswer & explanation
Correct answer: D. Azure VPN Gateway
Azure VPN Gateway allows you to create a secure, encrypted connection (VPN tunnel) over the public internet between your on-premises network and an Azure Virtual Network. This enables resources in Azure to communicate securely with on-premises resources.
Why the other options are wrong
- A. Azure Virtual Network provides network isolation and connectivity for Azure resources but doesn't create the secure tunnel to on-premises itself.
- B. Azure ExpressRoute provides a private, dedicated connection, not over the public internet.
- C. Azure Firewall provides network security and threat protection but doesn't establish encrypted tunnels to on-premises networks.
Azure VPN Gateway
A service that creates encrypted cross-premises connections between an Azure Virtual Network and on-premises locations over the public internet.
- Establishes secure VPN tunnels over the internet
- Connects Azure VNets to on-premises networks
- Supports Site-to-Site and Point-to-Site VPNs
- Used for hybrid cloud connectivity
Memory trick: VPN Gateway: Your secure internet bridge to Azure.