Courseiva
Describe Azure architecture and servicesmediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure architecture and services Practice Question

Which Azure service acts as a central networking hub connecting multiple virtual networks and on-premises networks together?

⚠ Common exam trap

Many exam-takers confuse Azure VNet Peering (a point-to-point connection) with a hub-and-spoke topology, but VNet Peering lacks the centralized routing and transitive connectivity that Virtual WAN provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Virtual WAN

Azure Virtual WAN is a networking service that provides a centralized hub-and-spoke architecture, enabling connectivity between multiple virtual networks (VNets) and on-premises networks through a single managed hub. It aggregates VPN, ExpressRoute, and VNet-to-VNet connections, simplifying routing and policy management across hybrid and multi-site environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure VNet Peering

    Why it's wrong here

    Azure VNet Peering links two virtual networks directly over the Microsoft backbone, but it is a point-to-point connection that requires you to establish peering between every pair of VNets you wish to interconnect. It does not provide centralized management, built-in branch-to-VNet connectivity, or automatically create a hub-and-spoke topology, so it cannot replace the orchestration and scale of Azure Virtual WAN for a large multi-site environment. While VNet Peering is a building block that Virtual WAN itself uses, it lacks the integrated routing, security policies, and branch connectivity that define Virtual WAN.

  • Azure Virtual WAN

    Why this is correct

    Azure Virtual WAN is a managed cloud networking service that acts as a central hub, providing transitive routing, connectivity, and security across many VNets, branch sites, and on-premises networks in a hub-and-spoke topology. It natively integrates with VPN, ExpressRoute, and point-to-site connections, offering built-in routing tables, encrypted traffic, and optional Firewall or NVAs for consistent policy enforcement. This makes it the correct choice when the architecture requires a scalable, centrally managed hub to interconnect multiple VNets and on-premises locations — exactly the scenario described in the question.

  • Azure ExpressRoute

    Why it's wrong here

    Azure ExpressRoute creates a dedicated private connection from your on-premises network to Azure, bypassing the public internet for low latency and higher reliability. However, it only establishes a single link between your data center and Azure’s edge — it does not by itself route traffic among many VNets or automatically aggregate multiple branch connections into a managed hub. ExpressRoute can be used as one of the connections into Azure Virtual WAN, but without Virtual WAN you would still need to manually configure the routing and interconnectivity between VNets and other branches, making it an incomplete solution for a full hub-and-spoke network.

  • Azure Private Link

    Why it's wrong here

    Azure Private Link enables private connectivity to PaaS services (such as Storage or SQL) through private IP addresses in your virtual network, essentially pulling a service endpoint into your VNet. It is not designed to connect multiple VNets to each other or to link on-premises branch offices; its whole purpose is providing controlled, private access to specific managed services. Thus, Private Link would not address the requirement of interconnecting VNets and on-premises networks with a centralized hub — that is the role of Azure Virtual WAN.

About these practice questions

Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.