Courseiva
Secure networking →easyMultiple Choice

AZ-500 Secure networking Practice Question

Your organization needs to securely connect an on-premises data center to Azure for disaster recovery. The connection must be encrypted and use the public internet. Which Azure service should you use?

⚠ Common exam trap

Watch out — candidates often confuse Azure ExpressRoute with VPN Gateway, assuming ExpressRoute can be used over the public internet, but ExpressRoute always uses a private, dedicated connection that does not traverse the internet, making it unsuitable when the requirement explicitly states 'use the public internet'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure VPN Gateway.

Azure VPN Gateway is the correct choice because it provides encrypted site-to-site IPsec/IKE VPN tunnels over the public internet, enabling secure connectivity between an on-premises data center and Azure for disaster recovery. This meets the requirement for encryption and use of the public internet, as VPN Gateway leverages standard protocols like IKEv2 and IPsec to protect data in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Front Door.

    Why it's wrong here

    Azure Front Door is a global, layer-7 HTTP(S) load-balancing and content-delivery service, not a site-to-site network tunnel. It makes routing decisions at the application layer and can apply WAF policies, but it does not create an encrypted IPsec data path between an on-premises network and an Azure VNet. Therefore it is unsuitable for the secure interconnection requirement.

  • ✗

    Azure ExpressRoute with private peering.

    Why it's wrong here

    Azure ExpressRoute with private peering provides dedicated, private Layer 3 connectivity via a carrier's MPLS network rather than over the public internet. It is a highly secure and reliable option, but it explicitly does not traverse the internet and requires an ExpressRoute circuit and a provider relationship. For an organization that needs to connect securely 'over the internet,' ExpressRoute does not match the stated connectivity model.

  • ✓

    Azure VPN Gateway.

    Why this is correct

    Azure VPN Gateway is correct because it implements a site-to-site IPsec/IKE VPN tunnel over the public internet between an on-premises VPN device and an Azure virtual network gateway. The tunnel encrypts traffic using industry-standard protocols such as IKEv2 and ESP, and the gateway supports active-active configurations and BGP for dynamic routing. This is the Azure service explicitly designed for secure internet-based hybrid connectivity.

  • ✗

    Azure DNS.

    Why it's wrong here

    Azure DNS is a global domain name resolution service that translates hostnames to IP addresses; it has no data-plane function for forwarding or tunneling network traffic. It cannot carry on-premises to Azure traffic, nor does it provide encryption or VPN termination. Selecting DNS would completely fail the requirement for secure site-to-site IP connectivity.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.