Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

You are configuring a site-to-site VPN connection between your on-premises network and Azure. You need to ensure that traffic between the networks is encrypted and authenticated. Which Azure service should you use?

⚠ Common exam trap

Test-takers frequently confuse Azure Virtual WAN (which includes VPN gateway capabilities) with the specific service required, or they assume ExpressRoute provides encryption by default, when in fact it does not encrypt traffic unless additional measures are taken.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure VPN Gateway

Azure VPN Gateway is the correct service because it provides encrypted and authenticated site-to-site VPN connections using IPsec/IKE protocols. It establishes a secure tunnel between your on-premises VPN device and the Azure VPN gateway, ensuring confidentiality and integrity of traffic across the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Virtual WAN

    Why it's wrong here

    Azure Virtual WAN is a comprehensive hub-and-spoke networking service that aggregates multiple connectivity components—including VPN gateways, ExpressRoute circuits, and Azure Firewall—into a single managed hub. For a straightforward site-to-site VPN, deploying Virtual WAN introduces significant architectural overhead, higher cost, and operational complexity, because you are provisioning an entire managed network infrastructure rather than a single VPN gateway. While it can technically include a VPN gateway, it is not the minimal, targeted service for this simple requirement.

  • ✗

    Azure ExpressRoute

    Why it's wrong here

    Azure ExpressRoute provides a private, dedicated connection from your on-premises network to Azure, bypassing the public internet for higher bandwidth and lower latency. However, by default ExpressRoute does not encrypt your traffic; the privacy it offers comes from isolated physical or virtual circuits, not from cryptographic protection. To achieve encrypted site-to-site connectivity over ExpressRoute, you would need to layer a separate VPN (such as Azure VPN Gateway) or use MACsec, but ExpressRoute alone does not fulfill the requirement of an encrypted IPsec tunnel.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a managed, cloud-native network security service that filters and logs traffic based on network and application rules, but it cannot terminate IPsec tunnels or function as a VPN gateway. It is designed to inspect and enforce security policies on traffic that passes through routing devices, not to establish encrypted site-to-site connections itself. Therefore, Azure Firewall is not a connectivity service; selecting it would be a category error, as it is a security enforcement point rather than a VPN endpoint.

  • ✓

    Azure VPN Gateway

    Why this is correct

    Azure VPN Gateway is the specific Azure service designed to create site-to-site (S2S) VPN connections by terminating IPsec/IKE tunnels between on-premises networks and Azure virtual networks. It supports multiple configurations, including active-active instances, BGP routing, and both policy-based and route-based VPN devices, making it the exact fit for the scenario. This is the correct choice because it directly provides the encrypted, secure tunnel required for a site-to-site VPN.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.