AZ-500 Secure networking Practice Question
You have an Azure subscription with a virtual network (VNet1) that hosts a SQL Managed Instance. You need to connect from an on-premises application to the SQL Managed Instance using a private IP address, with minimal latency and without traversing the public internet. The on-premises network has a high-speed ExpressRoute connection to Microsoft. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse ExpressRoute private peering with Microsoft peering or assume that a VPN with forced tunneling is sufficient, but forced tunneling only ensures outbound traffic goes through the VPN, not that inbound traffic avoids the internet, and it still uses the public internet path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect the on-premises network to Azure via ExpressRoute private peering and ensure the SQL Managed Instance subnet is reachable.
ExpressRoute private peering establishes a Layer 3 connection between on-premises and Azure, ensuring traffic to the SQL Managed Instance subnet traverses the Microsoft backbone network without touching the public internet. This provides the lowest latency and highest security for private IP connectivity, as the managed instance's private IP is directly routable over the ExpressRoute circuit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Connect the on-premises network to Azure via ExpressRoute private peering and ensure the SQL Managed Instance subnet is reachable.
Why this is correct
ExpressRoute private peering establishes a dedicated, private Layer 3 connection between your on-premises network and Azure, bypassing the public internet entirely. SQL Managed Instance is deployed into a dedicated subnet within your Azure VNet, so once that subnet is reachable via ExpressRoute (through BGP route exchange or appropriate routing), on-premises clients can directly connect to the instance's private IP address. This yields low latency, high throughput, and enterprise-grade reliability, and it does not require exposing a public endpoint or relying on a VPN tunnel.
- ✗
Configure a public endpoint on the SQL Managed Instance and allow the on-premises public IP.
Why it's wrong here
Configuring the SQL Managed Instance public endpoint would still route traffic over the public internet, and although you can restrict access by the on-premises public IP address, this violates the requirement for a private and low-latency connection. The public endpoint is disabled by default and requires an NSG rule on the managed instance's network security group to allow the IP, but it does not provide the same performance or security as a direct private link. Moreover, the on-premises public IP may be behind NAT, making access control and reliability problematic for enterprise workloads.
- ✗
Use Azure Private Link Service and connect via a VPN.
Why it's wrong here
Azure Private Link Service is not the right tool for this scenario; it is designed for third-party services behind a Standard Load Balancer to expose a private endpoint to consumers, not for connecting to an existing Azure PaaS service like SQL Managed Instance. SQL Managed Instance is already injected into your VNet's subnet, so you can reach its private IP directly without an additional Private Link layer. Adding a VPN on top of a Private Link Service introduces unnecessary complexity and an extra internet-based hop, which reduces performance and misses the point of a private connection.
- ✗
Create a site-to-site VPN connection and enable forced tunneling.
Why it's wrong here
Creating a site-to-site VPN and enabling forced tunneling is technically possible, but forced tunneling sends all internet-bound traffic from Azure to the on-premises network, which is not relevant to reaching SQL Managed Instance and adds needless routing complexity. Because a site-to-site VPN traverses the public internet, it experiences higher latency and more variable performance than a dedicated ExpressRoute circuit. The requirement calls for a robust, private, low-latency connection, making ExpressRoute private peering the superior choice even if a VPN could theoretically provide basic connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.