AZ-500 Global VNet Peering Practice Question
You are designing a secure network architecture for a multi-region application. You need to ensure that traffic between virtual networks in different Azure regions is encrypted and uses the Microsoft backbone network, and you must minimize latency. Which TWO configurations should you implement?
⚠ Common exam trap
Candidates often assume that a VPN gateway or ExpressRoute is required for encrypted cross-region VNet traffic, but VNet peering already routes traffic over the Microsoft backbone. Note that ExpressRoute with Microsoft peering is for Microsoft public services, not VNet-to-VNet connectivity, and does not provide encryption by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure VNet peering between the virtual networks.
Option B (Configure VNet peering between the virtual networks) is correct because Azure VNet peering routes traffic directly over the Microsoft backbone network, keeping it off the public internet and providing the lowest-latency path between VNets in different regions (global VNet peering). Option C is incorrect because ExpressRoute with Microsoft peering is used to reach Microsoft public services such as Microsoft 365 and Azure PaaS, not to connect virtual networks to each other, and ExpressRoute does not encrypt traffic by default. Option A is not required because gateway transit only lets a peered VNet share a VPN/ExpressRoute gateway; it does not itself provide encryption for VNet-to-VNet traffic. Option D is not the best choice because site-to-site VPN traffic traverses the public internet and typically adds latency compared with backbone-based peering. Option E is incorrect because Azure Firewall inspects and filters traffic but does not encrypt cross-region traffic or optimize latency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Gateway transit' on the peering to use a VPN gateway if needed, but not required for encryption.
Why it's wrong here
Gateway transit is for using a shared VPN gateway, but VNet peering itself can encrypt traffic when 'Configure traffic encryption' is enabled.
- ✓
Configure VNet peering between the virtual networks.
Why this is correct
VNet peering connects VNets using the Microsoft backbone and can be enabled globally.
- ✗
Use Azure ExpressRoute with Microsoft peering.
Why it's wrong here
ExpressRoute provides dedicated private connectivity but is more expensive and not necessary if VNet peering suffices.
- ✗
Deploy Azure VPN Gateway in each region and connect them via site-to-site VPN.
Why it's wrong here
VPN Gateway routes over the internet, not over the Microsoft backbone, and adds latency.
- ✗
Place an Azure Firewall in each region to inspect cross-region traffic.
Why it's wrong here
Firewall is for inspection, not for connectivity or encryption.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.