AZ-500 Secure networking Practice Question
You are configuring a site-to-site VPN connection between your on-premises network and Azure. You need to ensure that traffic between the networks is encrypted and authenticated. Which Azure service should you use?
⚠ Common exam trap
Test-takers frequently confuse Azure Virtual WAN (which includes VPN gateway capabilities) with the specific service required, or they assume ExpressRoute provides encryption by default, when in fact it does not encrypt traffic unless additional measures are taken.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure VPN Gateway
Azure VPN Gateway is the correct service because it provides encrypted and authenticated site-to-site VPN connections using IPsec/IKE protocols. It establishes a secure tunnel between your on-premises VPN device and the Azure VPN gateway, ensuring confidentiality and integrity of traffic across the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Virtual WAN
Why it's wrong here
Azure Virtual WAN is a comprehensive hub-and-spoke networking service that aggregates multiple connectivity components—including VPN gateways, ExpressRoute circuits, and Azure Firewall—into a single managed hub. For a straightforward site-to-site VPN, deploying Virtual WAN introduces significant architectural overhead, higher cost, and operational complexity, because you are provisioning an entire managed network infrastructure rather than a single VPN gateway. While it can technically include a VPN gateway, it is not the minimal, targeted service for this simple requirement.
- ✗
Azure ExpressRoute
Why it's wrong here
Azure ExpressRoute provides a private, dedicated connection from your on-premises network to Azure, bypassing the public internet for higher bandwidth and lower latency. However, by default ExpressRoute does not encrypt your traffic; the privacy it offers comes from isolated physical or virtual circuits, not from cryptographic protection. To achieve encrypted site-to-site connectivity over ExpressRoute, you would need to layer a separate VPN (such as Azure VPN Gateway) or use MACsec, but ExpressRoute alone does not fulfill the requirement of an encrypted IPsec tunnel.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, cloud-native network security service that filters and logs traffic based on network and application rules, but it cannot terminate IPsec tunnels or function as a VPN gateway. It is designed to inspect and enforce security policies on traffic that passes through routing devices, not to establish encrypted site-to-site connections itself. Therefore, Azure Firewall is not a connectivity service; selecting it would be a category error, as it is a security enforcement point rather than a VPN endpoint.
- ✓
Azure VPN Gateway
Why this is correct
Azure VPN Gateway is the specific Azure service designed to create site-to-site (S2S) VPN connections by terminating IPsec/IKE tunnels between on-premises networks and Azure virtual networks. It supports multiple configurations, including active-active instances, BGP routing, and both policy-based and route-based VPN devices, making it the exact fit for the scenario. This is the correct choice because it directly provides the encrypted, secure tunnel required for a site-to-site VPN.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.