Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium
A client is deploying a new critical application in Azure that requires dedicated, private connectivity from their on-premises data center to an Azure Virtual Network. This connection must offer consistent low latency and high bandwidth, bypassing the public internet entirely. They currently have no existing ExpressRoute circuits.
- AImplement VNet Peering between the on-premises network and Azure.
- BProvision an ExpressRoute circuit and connect it to an Azure VNet Gateway.
- CUse an Azure Point-to-Site VPN connection.
- DConfigure a Site-to-Site VPN Gateway connection.
Show answer & explanationAnswer & explanation
Correct answer: B. Provision an ExpressRoute circuit and connect it to an Azure VNet Gateway.
ExpressRoute provides a dedicated, private connection from an on-premises data center to Azure, bypassing the public internet. This ensures consistent low latency and high bandwidth, which are key requirements for critical applications.
Why the other options are wrong
- A. VNet Peering is used for connecting Azure VNets to each other, not for connecting on-premises networks to Azure.
- C. Point-to-Site VPN is for individual client machines connecting securely to Azure, not for a data center-to-VNet connection.
- D. Site-to-Site VPN uses the public internet, which does not guarantee consistent low latency or bypass the public internet entirely.
Azure ExpressRoute
Azure ExpressRoute extends an on-premises network into the Microsoft cloud over a private connection facilitated by a connectivity provider.
- Bypasses the public internet for enhanced security and reliability.
- Offers consistent low latency and high bandwidth.
- Requires an ExpressRoute circuit and an ExpressRoute Gateway in Azure.
Memory trick: For a dedicated connection, ExpressRoute is the private highway.