AZ-900 Describe Azure architecture and services Practice Question
A company has deployed applications in two separate Azure virtual networks (VNets) in the East US and West Europe regions. Each VNet contains multiple subnets with application servers and databases. The network team needs to enable direct, private IP connectivity between the VNets, ensuring that all traffic stays within the Azure backbone network and never traverses the public internet. The solution must also provide low latency for cross-region communication. They currently do not need a dedicated private connection to an on-premises datacenter. Which Azure service should they use?
⚠ Common exam trap
Test-takers frequently confuse Azure VPN Gateway with VNet Peering, assuming a VPN is required for cross-region connectivity, but VNet Peering natively supports global peering without any gateway or public internet exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VNet Peering
VNet Peering is the correct choice because it enables direct, private IP connectivity between two Azure virtual networks using the Microsoft backbone infrastructure, ensuring traffic never traverses the public internet. It provides low-latency, high-bandwidth cross-region communication without requiring a VPN gateway or dedicated circuits. Since the scenario involves only cloud-to-cloud connectivity (no on-premises requirement), VNet Peering is the simplest and most cost-effective solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway is incorrect because, while it can establish VNet-to-VNet connections, its default cross-region configuration often routes traffic over the public internet, violating the requirement for all traffic to stay within the Azure backbone and ensuring low latency. It is tempting as it provides secure, encrypted tunnels for connectivity. However, it would be the correct choice for connecting Azure VNets to on-premises networks securely over the internet, or for VNet-to-VNet connections where public internet transit is acceptable or when integrated with ExpressRoute.
When this WOULD be correct
A company needs to connect an on-premises datacenter to an Azure VNet securely over the internet using site-to-site VPN, or connect two VNets across regions when VNet peering is not available (e.g., overlapping address spaces).
- ✓
VNet Peering
Why this is correct
VNet peering (including global VNet peering) allows direct private IP connectivity between two VNets, regardless of region. Traffic remains on the Microsoft backbone, ensuring low latency and no exposure to the public internet. This solution is simple to configure, does not require gateways, and supports cross-region communication. It perfectly meets the requirements.
- ✗
Azure ExpressRoute
Why it's wrong here
Azure ExpressRoute provides a dedicated private connection from an on-premises network to Azure, not between two Azure VNets. While it offers low latency and private connectivity, it is designed for hybrid scenarios and is not intended for VNet-to-VNet connections. It is also costly and requires third-party providers. It does not address the requirement to connect VNets across regions.
- ✗
Azure Virtual WAN
Why it's wrong here
Azure Virtual WAN is a hub-and-spoke networking service that connects branches, sites, and VNets primarily through VPN or ExpressRoute gateways. While it can connect multiple VNets, it does so via a virtual hub that uses gateways, which adds complexity and cost compared to direct VNet peering. For a simple direct connection between two VNets, VNet peering is the appropriate service.
When this WOULD be correct
A company has multiple branch offices and Azure VNets across different regions, and they need a unified, automated networking solution that includes branch-to-branch connectivity, VPN/SD-WAN integration, and optional ExpressRoute. The requirement is to manage all network connections centrally with built-in routing and security policies.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓VNet PeeringCorrect answer▾
Why this is correct
VNet peering (including global VNet peering) allows direct private IP connectivity between two VNets, regardless of region. Traffic remains on the Microsoft backbone, ensuring low latency and no exposure to the public internet. This solution is simple to configure, does not require gateways, and supports cross-region communication. It perfectly meets the requirements.
✗Azure VPN GatewayWrong answer — click to see why▾
Why this is wrong here
Azure VPN Gateway connects on-premises networks or VNets over the public internet using IPsec tunnels, which introduces internet dependency and higher latency, contradicting the requirement for private IP connectivity within the Azure backbone with low latency.
★ When this WOULD be the correct answer
A company needs to connect an on-premises datacenter to an Azure VNet securely over the internet using site-to-site VPN, or connect two VNets across regions when VNet peering is not available (e.g., overlapping address spaces).
Why candidates choose this
Candidates may think VPN Gateway is the standard way to connect networks, overlooking that VNet peering provides direct, private, low-latency connectivity within Azure without internet traversal.
✗Azure Virtual WANWrong answer — click to see why▾
Why this is wrong here
Azure Virtual WAN is a networking service that provides optimized and automated branch-to-branch and branch-to-Azure connectivity, but it is overkill for simply connecting two VNets. The question specifies no need for on-premises connectivity or multiple branch sites, making VNet Peering the simpler and correct choice.
★ When this WOULD be the correct answer
A company has multiple branch offices and Azure VNets across different regions, and they need a unified, automated networking solution that includes branch-to-branch connectivity, VPN/SD-WAN integration, and optional ExpressRoute. The requirement is to manage all network connections centrally with built-in routing and security policies.
Why candidates choose this
Candidates may think Virtual WAN is required for any cross-region VNet connectivity because it is a managed service that handles routing, but they overlook that VNet Peering is the direct and simpler solution for connecting just two VNets.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Azure Regions and Geographies
Key term
Region
A region is a distinct geographic location where a cloud provider operates multiple data centers that are connected by low-latency networks and provide cloud services.
Key term
VNet
A virtual private network inside a cloud provider that lets you securely connect and isolate your cloud resources.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.