Courseiva
Secure networking →hardMultiple Select

AZ-500 Global VNet Peering Practice Question

You are designing a secure network architecture for a multi-region application. You need to ensure that traffic between virtual networks in different Azure regions is encrypted and uses the Microsoft backbone network, and you must minimize latency. Which TWO configurations should you implement?

⚠ Common exam trap

Candidates often assume that a VPN gateway or ExpressRoute is required for encrypted cross-region VNet traffic, but VNet peering already routes traffic over the Microsoft backbone. Note that ExpressRoute with Microsoft peering is for Microsoft public services, not VNet-to-VNet connectivity, and does not provide encryption by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure VNet peering between the virtual networks.

Option B (Configure VNet peering between the virtual networks) is correct because Azure VNet peering routes traffic directly over the Microsoft backbone network, keeping it off the public internet and providing the lowest-latency path between VNets in different regions (global VNet peering). Option C is incorrect because ExpressRoute with Microsoft peering is used to reach Microsoft public services such as Microsoft 365 and Azure PaaS, not to connect virtual networks to each other, and ExpressRoute does not encrypt traffic by default. Option A is not required because gateway transit only lets a peered VNet share a VPN/ExpressRoute gateway; it does not itself provide encryption for VNet-to-VNet traffic. Option D is not the best choice because site-to-site VPN traffic traverses the public internet and typically adds latency compared with backbone-based peering. Option E is incorrect because Azure Firewall inspects and filters traffic but does not encrypt cross-region traffic or optimize latency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Gateway transit' on the peering to use a VPN gateway if needed, but not required for encryption.

    Why it's wrong here

    Gateway transit is for using a shared VPN gateway, but VNet peering itself can encrypt traffic when 'Configure traffic encryption' is enabled.

  • ✓

    Configure VNet peering between the virtual networks.

    Why this is correct

    VNet peering connects VNets using the Microsoft backbone and can be enabled globally.

  • ✗

    Use Azure ExpressRoute with Microsoft peering.

    Why it's wrong here

    ExpressRoute provides dedicated private connectivity but is more expensive and not necessary if VNet peering suffices.

  • ✗

    Deploy Azure VPN Gateway in each region and connect them via site-to-site VPN.

    Why it's wrong here

    VPN Gateway routes over the internet, not over the Microsoft backbone, and adds latency.

  • ✗

    Place an Azure Firewall in each region to inspect cross-region traffic.

    Why it's wrong here

    Firewall is for inspection, not for connectivity or encryption.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.