Courseiva
Secure networking →easyMultiple Select

AZ-500 Secure networking Practice Question

Which TWO of the following are supported ways to connect an on-premises network to Azure?

⚠ Common exam trap

It's easy for candidates to confuse Azure Bastion (a secure access service for VMs) with a network connectivity solution, or assuming Point-to-Site VPN can connect an entire on-premises network when it only supports individual client connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure ExpressRoute

Azure ExpressRoute (B) is correct because it provides a private, dedicated connection between an on-premises network and Azure through a connectivity provider, bypassing the public internet. Site-to-Site VPN (D) is correct because it establishes an IPsec/IKE VPN tunnel over the public internet between an on-premises VPN device and an Azure VPN gateway, connecting entire networks. Azure Bastion (A) is not a network-to-network connection method; it provides secure RDP/SSH access to VMs through the Azure portal over TLS. Point-to-Site VPN (C) connects an individual client computer to an Azure virtual network, not an on-premises network as a whole. Azure Front Door (E) is a global HTTP/HTTPS application delivery and load-balancing service, not a site-to-site connectivity solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion is a fully managed PaaS service that provides secure RDP and SSH access to virtual machines directly through the Azure portal, using TLS and WebSockets behind an Azure-managed bastion subnet. It does not establish any network path between a customer's on-premises or remote network and Azure; instead, it proxies management traffic within Azure's network. Therefore, it is a remote administration tool, not a hybrid connectivity solution, and cannot be used to connect an external network to a VNet.

  • ✓

    Azure ExpressRoute

    Why this is correct

    Azure ExpressRoute is a dedicated, private network connection that extends an enterprise's on-premises infrastructure into Azure over a service provider's MPLS or similar reliable infrastructure, bypassing the public internet entirely. It uses BGP for dynamic routing and offers higher reliability, lower latency, and fixed bandwidth options, with regional redundancy. As a result, it is one of the two supported ways to connect an organization's network directly to Azure for hybrid deployments.

  • ✗

    Point-to-Site VPN

    Why it's wrong here

    Point-to-Site (P2S) VPN is a secure connection from an individual client computer to an Azure virtual network, using SSTP, IKEv2, or OpenVPN, typically from a remote worker's laptop. It does not connect an entire on-premises network or multiple devices; each client must establish its own independent VPN session. Because the question concerns connecting whole networks, P2S is not a supported site-to-site option, even though it is a valid remote-access connection method.

  • ✓

    Site-to-Site VPN

    Why this is correct

    Site-to-Site VPN is an IPsec/IKE encrypted tunnel that connects an on-premises VPN gateway device to an Azure VPN gateway over the public internet, enabling the entire on-premises network to securely reach Azure resources. It is a standard, supported hybrid connectivity solution that offers persistent, network-of-networks connectivity, and is often paired with ExpressRoute as a failover path. This is one of the two correct ways to connect an organization's network to Azure.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is an application delivery and global load balancing service that routes HTTP/S traffic across the internet based on latency and availability, providing acceleration, SSL offload, and WAF capabilities. It operates at the application layer (L7) and does not create any Layer-3/4 tunnel or private network path between an on-premises network and Azure. Thus, it cannot serve as a hybrid network connection; it only manages public web traffic, making it an incorrect choice for this scenario.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.