Azure ExpressRoute: Dedicated Private Connection to Azure
A company has multiple on-premises sites that need to connect to Azure over high-throughput, low-latency private connections. They want a dedicated private connection that does not traverse the internet. Which Azure service should they use?
Quick Answer
Azure ExpressRoute is the correct choice because it provides a dedicated private connection from on-premises sites to Azure that does not traverse the internet, ensuring high throughput and low latency through a Layer 3 VPN or direct peering via a connectivity provider. This bypasses public internet routing entirely, making it ideal for hybrid scenarios requiring consistent performance and security. On the AZ-900 exam, this question tests your understanding of Azure networking services and their use cases, often appearing alongside VPN Gateway as a distractor—remember that VPN Gateway uses the internet over encrypted tunnels, while ExpressRoute is truly private and internet-free. A common trap is confusing ExpressRoute with a site-to-site VPN; the key differentiator is that ExpressRoute bypasses the internet completely, offering higher reliability and bandwidth. Memory tip: think “ExpressRoute = Express lane, no internet traffic jams.”
⚠ Common exam trap
Many candidates confuse Azure VPN Gateway's 'private tunnel' (which still uses the internet) with a truly private connection, or assume Virtual WAN itself provides the dedicated link, when in fact ExpressRoute is the only service that offers a dedicated, internet-free private connection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure ExpressRoute
Azure ExpressRoute provides a dedicated private connection from on-premises sites to Azure that does not traverse the public internet, ensuring high throughput and low latency. It uses a Layer 3 VPN or direct peering via a connectivity provider, bypassing internet-based routing entirely. This makes it ideal for scenarios requiring consistent performance and security for hybrid connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway uses the public internet to create encrypted tunnels, not a dedicated private connection.
When this WOULD be correct
A company needs to connect multiple on-premises sites to Azure over the internet with encrypted tunnels, and cost is a primary concern. They do not require dedicated private bandwidth or low latency.
- ✓
Azure ExpressRoute
Why this is correct
ExpressRoute offers a private, dedicated connection to Azure, ensuring high throughput and low latency.
- ✗
Azure Virtual WAN
Why it's wrong here
Azure Virtual WAN is a networking service that can incorporate ExpressRoute and VPN, but the question asks for the specific private connection service.
When this WOULD be correct
An exam scenario where Azure Virtual WAN would be correct: 'A company has multiple branch offices and needs to connect them to Azure and to each other with automated, optimized routing. They want to use a combination of VPN and ExpressRoute connections managed through a single dashboard.'
- ✗
Azure Peering Service
Why it's wrong here
Azure Peering Service improves connectivity over the internet, but it is not a dedicated private connection.
When this WOULD be correct
An exam question might ask: 'A company wants to improve the reliability and performance of their internet-based connections to Microsoft 365 and Dynamics 365. Which service should they use?' In that case, Azure Peering Service would be correct as it enhances connectivity to Microsoft SaaS applications over the public internet.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure ExpressRouteCorrect answer▾
Why this is correct
ExpressRoute offers a private, dedicated connection to Azure, ensuring high throughput and low latency.
✗Azure VPN GatewayWrong answer — click to see why▾
Why this is wrong here
Azure VPN Gateway connects sites over the internet using encrypted tunnels, not dedicated private connections. The question specifies a private connection that does not traverse the internet, which VPN Gateway does not fulfill.
★ When this WOULD be the correct answer
A company needs to connect multiple on-premises sites to Azure over the internet with encrypted tunnels, and cost is a primary concern. They do not require dedicated private bandwidth or low latency.
Why candidates choose this
Candidates may confuse VPN Gateway with ExpressRoute because both provide site-to-site connectivity, but they overlook the requirement for a private, non-internet connection.
✗Azure Virtual WANWrong answer — click to see why▾
Why this is wrong here
Azure Virtual WAN is a networking service that provides optimized and automated branch-to-branch and branch-to-Azure connectivity, but it does not offer dedicated private connections that bypass the internet. It typically uses VPN or ExpressRoute under the hood, but the question specifically requires a dedicated private connection that does not traverse the internet, which is the defining feature of ExpressRoute, not Virtual WAN itself.
★ When this WOULD be the correct answer
An exam scenario where Azure Virtual WAN would be correct: 'A company has multiple branch offices and needs to connect them to Azure and to each other with automated, optimized routing. They want to use a combination of VPN and ExpressRoute connections managed through a single dashboard.'
Why candidates choose this
Candidates may confuse Virtual WAN as a direct alternative to ExpressRoute because it can integrate ExpressRoute circuits, but they overlook that Virtual WAN is a hub-and-spoke architecture that relies on underlying connectivity methods, not a dedicated private connection itself.
✗Azure Peering ServiceWrong answer — click to see why▾
Why this is wrong here
Azure Peering Service is designed to optimize connectivity to Microsoft cloud services over the internet, not to provide dedicated private connections that bypass the internet. It does not offer the high-throughput, low-latency private connectivity required in the question.
★ When this WOULD be the correct answer
An exam question might ask: 'A company wants to improve the reliability and performance of their internet-based connections to Microsoft 365 and Dynamics 365. Which service should they use?' In that case, Azure Peering Service would be correct as it enhances connectivity to Microsoft SaaS applications over the public internet.
Why candidates choose this
Candidates may confuse 'peering' with 'private connection' and assume that Azure Peering Service provides a dedicated private link, when in fact it is an internet-based optimization service.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Regions and Geographies
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Azure ExpressRoute
Azure ExpressRoute is a dedicated, private, and high-speed network connection from your on-premises data center to Microsoft's cloud, bypassing the public internet for better reliability, security, and performance.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company needs to connect their on-premises network to Azure with a dedicated, private, and high-bandwidth connection that does not traverse the public internet. They require an SLA for availability and performance. Which Azure service should they use?
hard- A.Azure VPN Gateway
- ✓ B.Azure ExpressRoute
- C.Azure Virtual WAN
- D.Azure Peering Service
Why B: Azure ExpressRoute is the correct choice because it provides a dedicated, private connection from on-premises networks to Azure that does not traverse the public internet. It offers a Service-Level Agreement (SLA) for availability (e.g., 99.95% for a single connection with redundancy) and performance, which is not guaranteed over internet-based VPNs. This meets the requirement for high bandwidth, privacy, and a guaranteed SLA.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.