AZ-500 Secure networking Practice Question
Which TWO of the following are supported ways to connect an on-premises network to Azure?
⚠ Common exam trap
It's easy for candidates to confuse Azure Bastion (a secure access service for VMs) with a network connectivity solution, or assuming Point-to-Site VPN can connect an entire on-premises network when it only supports individual client connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure ExpressRoute
Azure ExpressRoute (B) is correct because it provides a private, dedicated connection between an on-premises network and Azure through a connectivity provider, bypassing the public internet. Site-to-Site VPN (D) is correct because it establishes an IPsec/IKE VPN tunnel over the public internet between an on-premises VPN device and an Azure VPN gateway, connecting entire networks. Azure Bastion (A) is not a network-to-network connection method; it provides secure RDP/SSH access to VMs through the Azure portal over TLS. Point-to-Site VPN (C) connects an individual client computer to an Azure virtual network, not an on-premises network as a whole. Azure Front Door (E) is a global HTTP/HTTPS application delivery and load-balancing service, not a site-to-site connectivity solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion is a fully managed PaaS service that provides secure RDP and SSH access to virtual machines directly through the Azure portal, using TLS and WebSockets behind an Azure-managed bastion subnet. It does not establish any network path between a customer's on-premises or remote network and Azure; instead, it proxies management traffic within Azure's network. Therefore, it is a remote administration tool, not a hybrid connectivity solution, and cannot be used to connect an external network to a VNet.
- ✓
Azure ExpressRoute
Why this is correct
Azure ExpressRoute is a dedicated, private network connection that extends an enterprise's on-premises infrastructure into Azure over a service provider's MPLS or similar reliable infrastructure, bypassing the public internet entirely. It uses BGP for dynamic routing and offers higher reliability, lower latency, and fixed bandwidth options, with regional redundancy. As a result, it is one of the two supported ways to connect an organization's network directly to Azure for hybrid deployments.
- ✗
Point-to-Site VPN
Why it's wrong here
Point-to-Site (P2S) VPN is a secure connection from an individual client computer to an Azure virtual network, using SSTP, IKEv2, or OpenVPN, typically from a remote worker's laptop. It does not connect an entire on-premises network or multiple devices; each client must establish its own independent VPN session. Because the question concerns connecting whole networks, P2S is not a supported site-to-site option, even though it is a valid remote-access connection method.
- ✓
Site-to-Site VPN
Why this is correct
Site-to-Site VPN is an IPsec/IKE encrypted tunnel that connects an on-premises VPN gateway device to an Azure VPN gateway over the public internet, enabling the entire on-premises network to securely reach Azure resources. It is a standard, supported hybrid connectivity solution that offers persistent, network-of-networks connectivity, and is often paired with ExpressRoute as a failover path. This is one of the two correct ways to connect an organization's network to Azure.
- ✗
Azure Front Door
Why it's wrong here
Azure Front Door is an application delivery and global load balancing service that routes HTTP/S traffic across the internet based on latency and availability, providing acceleration, SSL offload, and WAF capabilities. It operates at the application layer (L7) and does not create any Layer-3/4 tunnel or private network path between an on-premises network and Azure. Thus, it cannot serve as a hybrid network connection; it only manages public web traffic, making it an incorrect choice for this scenario.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.