Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium

A financial institution is implementing a new trading platform in Azure. The platform requires a dedicated, private, and high-bandwidth connection between its on-premises data center and Azure, ensuring predictable network performance and low latency. The solution must bypass the public internet. Which Azure networking service should be chosen?

  1. AAzure Load Balancer
  2. BAzure Virtual WAN
  3. CAzure ExpressRoute
  4. DAzure VPN Gateway
Show answer & explanation

Correct answer: C. Azure ExpressRoute

Azure ExpressRoute provides a private, dedicated, and high-bandwidth connection between on-premises networks and Azure. It bypasses the public internet, offering predictable performance, low latency, and enhanced security, which are critical for financial institutions.

Why the other options are wrong

  • A. Azure Load Balancer distributes traffic within Azure or to on-premises, but it does not establish the private network connectivity itself.
  • B. Azure Virtual WAN is a networking service that provides optimized and automated branch connectivity to Azure, but ExpressRoute is the underlying technology for the private connection itself.
  • D. Azure VPN Gateway establishes encrypted connections over the public internet, which does not meet the requirement to bypass the public internet for predictable performance.

Azure ExpressRoute

A service that enables you to create private connections between Azure data centers and infrastructure that's on-premises or in a colocation environment. ExpressRoute connections do not go over the public internet.

  • Private, dedicated connection
  • Bypasses the public internet
  • Offers higher bandwidth and lower latency than VPNs
  • Enhanced security and reliability

Memory trick: ExpressRoute is the 'express' way, not the 'public' way.

More Design infrastructure solutions questions