AZ-500 Secure networking Practice Question
Your organization has a Microsoft Entra ID tenant and uses Azure Virtual Desktop (AVD). You need to ensure that AVD session hosts in a virtual network can access on-premises resources securely without exposing the session hosts to the internet. The on-premises network is connected to Azure via ExpressRoute. All AVD traffic should be routed through the ExpressRoute connection. You have already deployed a reverse connect transport for AVD. What else should you configure to meet the requirements?
⚠ Common exam trap
A common mix-up: candidates confuse VNet peering (which connects VNets within Azure) with hybrid connectivity to on-premises, or mistakenly think a private endpoint for the control plane alone satisfies all routing requirements for session host traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a user-defined route (UDR) in the AVD subnet for the on-premises IP prefixes with next hop to the ExpressRoute gateway.
Adding a user-defined route (UDR) in the AVD subnet for on-premises IP prefixes with the next hop set to the ExpressRoute gateway forces all traffic destined for on-premises resources to traverse the ExpressRoute connection. This ensures secure, private connectivity without exposing session hosts to the internet, while the reverse connect transport already handles AVD control plane traffic securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure VNet peering between the AVD virtual network and the on-premises network.
Why it's wrong here
VNet peering connects two Azure virtual networks directly over Microsoft's backbone; it cannot extend to an on-premises network, which is outside Azure. The on-premises side must be attached via an ExpressRoute circuit, a Site-to-Site VPN, or a similar gateway-based connection. Even with peering, a session host in the AVD subnet would still rely on default routing to reach on-premises prefixes unless explicit routes point to that gateway. Therefore, VNet peering is not the mechanism for this scenario.
- ✓
Add a user-defined route (UDR) in the AVD subnet for the on-premises IP prefixes with next hop to the ExpressRoute gateway.
Why this is correct
A user-defined route (UDR) associated with the AVD subnet can explicitly direct traffic destined for the on-premises IP prefixes to the ExpressRoute virtual network gateway by setting the next hop type to 'VirtualNetworkGateway'. This forces all matching traffic from session hosts to traverse the ExpressRoute connection instead of default internet routing, ensuring secure and predictable connectivity to on-premises resources. Without such a route, traffic might bypass the gateway or use an unintended path, depending on the existing route table.
- ✗
Disable reverse connect transport and allow inbound RDP traffic from the internet.
Why it's wrong here
Disabling reverse connect transport would break Azure Virtual Desktop's core connectivity model, which relies on session hosts initiating outbound connections to the AVD control plane. Allowing direct inbound RDP from the internet would expose session hosts to public attack surface, violating security requirements and standard AVD architecture. Even if a route to on-premises exists, this option does not address the routing problem and introduces significant risk, making it clearly incorrect.
- ✗
Create a private endpoint for the AVD control plane.
Why it's wrong here
A private endpoint provides a private IP address for accessing an Azure PaaS service (like the AVD control plane) from within a virtual network, but it does not control routing between a subnet and on-premises networks. The AVD control plane's private endpoint might improve control-plane security, yet traffic destined to on-premises IP prefixes still needs an explicit route, such as a UDR to the ExpressRoute gateway. Therefore, creating a private endpoint does not solve the connectivity requirement described in the question.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.