Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium

A client is deploying a new critical application in Azure that requires dedicated, private connectivity from their on-premises data center to an Azure Virtual Network. This connection must offer consistent low latency and high bandwidth, bypassing the public internet entirely. They currently have no existing ExpressRoute circuits.

  1. AImplement VNet Peering between the on-premises network and Azure.
  2. BProvision an ExpressRoute circuit and connect it to an Azure VNet Gateway.
  3. CUse an Azure Point-to-Site VPN connection.
  4. DConfigure a Site-to-Site VPN Gateway connection.
Show answer & explanation

Correct answer: B. Provision an ExpressRoute circuit and connect it to an Azure VNet Gateway.

ExpressRoute provides a dedicated, private connection from an on-premises data center to Azure, bypassing the public internet. This ensures consistent low latency and high bandwidth, which are key requirements for critical applications.

Why the other options are wrong

  • A. VNet Peering is used for connecting Azure VNets to each other, not for connecting on-premises networks to Azure.
  • C. Point-to-Site VPN is for individual client machines connecting securely to Azure, not for a data center-to-VNet connection.
  • D. Site-to-Site VPN uses the public internet, which does not guarantee consistent low latency or bypass the public internet entirely.

Azure ExpressRoute

Azure ExpressRoute extends an on-premises network into the Microsoft cloud over a private connection facilitated by a connectivity provider.

  • Bypasses the public internet for enhanced security and reliability.
  • Offers consistent low latency and high bandwidth.
  • Requires an ExpressRoute circuit and an ExpressRoute Gateway in Azure.

Memory trick: For a dedicated connection, ExpressRoute is the private highway.

More Implement and manage virtual networking questions