Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium

A global enterprise requires a highly available and scalable network solution to connect its numerous branch offices worldwide to Azure and to each other. The solution must support site-to-site VPNs, ExpressRoute connectivity, and provide centralized network management and security policies across all connections. Which Azure networking service is BEST suited for this hub-and-spoke topology across a global network?

  1. AAzure Virtual Network Gateway
  2. BAzure Firewall
  3. CAzure Virtual WAN
  4. DAzure Load Balancer
Show answer & explanation

Correct answer: C. Azure Virtual WAN

Azure Virtual WAN is a networking service that provides optimized, automated, and global connectivity. It acts as a unified interface for connecting branch offices, ExpressRoute circuits, and Azure VNets, providing centralized network management, routing, and security. This makes it ideal for a global hub-and-spoke architecture.

Why the other options are wrong

  • A. Azure Virtual Network Gateway connects individual VNets or on-premises networks but does not provide centralized global management for many branches.
  • B. Azure Firewall provides network security but is not a global connectivity solution for multiple sites and ExpressRoute.
  • D. Azure Load Balancer distributes traffic to backend resources and is not a global network connectivity and management solution.

Azure Virtual WAN

A unified networking solution that brings together many networking, security, and routing functionalities to provide a single operational interface.

  • Global, scalable network connectivity
  • Integrates VPN, ExpressRoute, and VNet connections
  • Centralized network management and security

Memory trick: Virtual WAN: The 'WAN' for a world of connections.

More Design infrastructure solutions questions