AZ-500 Secure networking Practice Question
A company wants to deploy an Azure VPN Gateway in active-active mode to ensure high availability for their site-to-site VPN connection. They have two on-premises VPN devices, each with a distinct public IP address. What is the minimum configuration required for the Azure VPN Gateway to utilize both on-premises devices?
⚠ Common exam trap
Watch out — candidates often think a single local network gateway can hold multiple on-premises IPs or that BGP alone can handle dual tunnels, but Azure requires a separate local network gateway per on-premises device to establish distinct IPsec SAs in active-active mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create two local network gateways, each with one on-premises public IP, and connect each to a different IP of the VPN gateway.
Active-active mode requires two distinct IP addresses on the Azure VPN gateway, and each on-premises VPN device must be represented by its own local network gateway. By creating two local network gateways (one per on-premises public IP) and connecting each to a different Azure VPN gateway IP, you establish two independent IPsec tunnels, achieving high availability. This configuration ensures that if one on-premises device or one Azure instance fails, traffic can still flow through the other tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create two local network gateways, each with one on-premises public IP, and connect each to a different IP of the VPN gateway.
Why this is correct
In active-active mode, the Azure VPN gateway is deployed with two public IP addresses, and the correct configuration requires two separate on-premises VPN devices, each represented by its own local network gateway. By creating a local network gateway for each on-premises public IP and connecting each one to a different gateway IP address via separate connections, you establish two independent IPsec tunnels that operate concurrently. This satisfies high availability because failure of one on-premises device or one Azure gateway instance still leaves a functional tunnel. Without this placement — one local network gateway per on-premises IP — the gateway cannot build active-active tunnels to two distinct on-premises endpoints.
- ✗
Create one local network gateway that includes both on-premises IP addresses and enable BGP on the connection.
Why it's wrong here
A local network gateway resource represents a single on-premises site and accepts only one public IP address for the remote VPN device; you cannot include two on-premises IP addresses in a single local network gateway definition. Although enabling BGP on the connection supports dynamic routing and automatic failover between tunnels, BGP does not change the fundamental constraint that each local network gateway must point to exactly one on-premises endpoint. To utilize two on-premises IPs, you must create two local network gateways regardless of BGP use, which means this option is not a valid alternative.
- ✗
Use active-passive mode and configure a second VPN gateway in the same virtual network.
Why it's wrong here
A virtual network can contain only one VPN gateway resource, so you cannot deploy a second active-passive VPN gateway into the same VNet to achieve high availability. Active-passive mode already provides a redundant gateway instance, but that standby instance is not used for active traffic and does not leverage two on-premises devices; it only fails over to the standby tunnel. Furthermore, active-passive mode still uses a single gateway with one public IP (or optional BGP), and it does not meet the requirement of running active-active connections to separate on-premises devices concurrently.
- ✗
Deploy two separate VPN gateways in different Azure regions.
Why it's wrong here
Deploying two separate VPN gateways in different Azure regions provides regional redundancy, also known as geo-redundancy, which is a different availability scenario than active-active mode within a single gateway. These gateways would belong to different virtual networks and would require additional configuration such as VNet-to-VNet peering or a shared on-premises device, and they do not form two active tunnels from the same gateway to the same on-premises site. The question specifically asks for active-active mode, which is a property of a single VPN gateway instance using two public IPs, so this regional approach does not satisfy the stated architecture.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.