AZ-500 Secure networking Practice Question
You need to secure traffic between two VNets in different Azure regions. The VNets contain virtual machines that must communicate over private IP addresses. Which Azure service should you use?
⚠ Common exam trap
Candidates often confuse Azure VPN Gateway (which also connects VNets) with VNet peering, but VPN Gateway uses encrypted tunnels over the internet and incurs higher latency and throughput limitations, whereas VNet peering provides direct, private, high-bandwidth connectivity over the Microsoft backbone without a gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VNet peering
VNet peering enables direct, private IP connectivity between two VNets in different Azure regions (global VNet peering). Traffic flows over the Microsoft backbone network, not the public internet, ensuring low-latency and secure communication between virtual machines using private IP addresses without requiring a gateway or additional appliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, stateful firewall-as-a-service that filters and logs traffic based on network and application rules. It does not create a network path or route between VNets; it must be deployed in a hub VNet and rely on underlying connectivity like peering or VPN to inspect traffic. Therefore, while it can secure traffic, it cannot by itself establish the inter-VNet connectivity needed in this scenario.
- ✓
VNet peering
Why this is correct
VNet peering establishes a direct, low-latency connection between two virtual networks using Microsoft's backbone infrastructure, allowing private IP addresses to communicate across regions without going through the internet or a gateway. For the requirement to secure traffic between two VNets in different Azure regions, peering provides the connectivity layer, and security can then be applied via network security groups or a firewall. Peering is the correct answer because it is the native Azure mechanism for cross-region VNet-to-VNet private IP communication.
- ✗
Azure VPN Gateway
Why it's wrong here
A VPN gateway can connect VNets across regions via an encrypted IPsec tunnel, but this approach is intended for site-to-site or point-to-site connectivity and requires a gateway in each VNet, adding complexity and cost. Traffic over a VPN gateway traverses the public internet between Azure regions rather than using Azure's private backbone, so it is not the native, low-latency path for inter-VNet communication. Because the goal is simply to secure traffic between two VNets, VNet peering directly provides private connectivity, making the VPN gateway an incorrect and over-engineered option.
- ✗
ExpressRoute
Why it's wrong here
ExpressRoute enables a private, dedicated connection from an on-premises network to Azure, not from one Azure VNet to another. To use ExpressRoute for VNet-to-VNet, you would need to set up two separate circuits and route traffic between them, which is far more complex and requires third-party providers. It does not create a direct peering relationship between virtual networks, and it does not address the requirement for cross-region connectivity between two VNets in Azure. Thus, ExpressRoute is incorrect for this scenario because it isn't designed for inter-VNet communication.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.