AZ-500 Secure networking Practice Question
Which TWO are valid connection methods for Azure VPN Gateway? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse VNet-to-VNet as a distinct connection method when it is actually a specific use case of Site-to-Site, and they may also mistakenly think Azure Bastion or ExpressRoute are VPN gateway connection types when they are separate Azure services with different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Point-to-Site
Point-to-Site (P2S) is a valid connection method for Azure VPN Gateway because it allows individual client computers to connect securely to an Azure virtual network from anywhere using the SSTP, IKEv2, or OpenVPN protocols. This method is ideal for remote workers who need encrypted access without requiring a site-level VPN device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Point-to-Site
Why this is correct
Azure VPN Gateway's Point-to-Site method allows individual client computers to establish a secure connection to a VNet from any location, using SSTP, IKEv2, or OpenVPN protocols. Each client authenticates via certificates or Microsoft Entra ID, and traffic is wrapped in IPsec for IKEv2/OpenVPN or SSL/TLS for SSTP. It is one of the two primary VPN connection methods, distinct from Site-to-Site because it does not require a public-facing VPN device on the customer side.
- ✗
VNet-to-VNet
Why it's wrong here
VNet-to-VNet is not a distinct VPN gateway connection method; it's a configuration that connects two Azure VNets using the same IPsec/IKE Site-to-Site protocol. You create VPN gateways in both VNets and establish a Site-to-Site connection between them, optionally with BGP for dynamic routing. Because it relies on the S2S mechanism, it is considered a scenario of Site-to-Site rather than a separate method listed by the VPN gateway.
- ✓
Site-to-Site
Why this is correct
Site-to-Site creates an IPsec/IKE tunnel between an on-premises VPN device and the Azure VPN gateway, enabling the entire on-premises network to securely communicate with the VNet as if it were directly attached. Configuration requires a public IP on the local VPN device, a pre-shared key, and typically a BGP or static route. This method is one of the two valid connection methods; it is distinct from P2S because it aggregates whole networks rather than individual client sessions.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion is a fully managed platform service that provides secure, seamless RDP and SSH access to virtual machines directly in the Azure portal over TLS, without requiring a public IP address on the VM. It acts as a jump host brokering connections, not as a VPN tunnel that encrypts all traffic between a network and Azure. Therefore it cannot be used as a VPN gateway connection method, as it serves a completely different remote-access purpose.
- ✗
ExpressRoute
Why it's wrong here
ExpressRoute creates a private, dedicated network connection from on-premises infrastructure to Azure through a connectivity provider, bypassing the public internet entirely. It does not use IPsec or any VPN tunneling protocol and is implemented with an ExpressRoute gateway, not a VPN gateway. Although often used alongside a VPN gateway for failover, it is a separate networking service rather than a VPN connection method.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.