Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Which THREE components are required to implement a secure hybrid network architecture using Azure VPN Gateway? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A local network gateway resource in Azure.

Option A (a local network gateway resource in Azure) is required because it defines the on-premises VPN device's public IP address and address spaces, which Azure uses as the remote endpoint for the site-to-site tunnel. Option B (a connection resource with a shared key) is required because the connection object links the virtual network gateway to the local network gateway and carries the pre-shared key (PSK) used for IKE/IPsec authentication. Option D (a virtual network gateway in Azure) is required because it is the Azure-side VPN Gateway (VpnGw SKU) that terminates the IPsec/IKE tunnel and routes traffic into the virtual network. Option C (an ExpressRoute circuit) does not belong because ExpressRoute is a private dedicated-circuit connectivity model, not a VPN Gateway component, and the scenario specifies VPN Gateway. Option E (an Azure Firewall) does not belong because it is a managed network security service for traffic filtering and is not a prerequisite for establishing a VPN Gateway site-to-site connection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A local network gateway resource in Azure.

    Why this is correct

    The local network gateway is a logical Azure object that points to your on-premises VPN device by its public IP address and defines the on-premises address space(s) that Azure should advertise over the tunnel. Without it, the Azure virtual network gateway has no remote endpoint to establish an IPsec session with, nor any knowledge of which on-premises routes should be reachable. It is therefore a mandatory configuration item for a Site-to-Site VPN.

  • ✓

    A connection resource with a shared key.

    Why this is correct

    A connection resource with a shared key is the Site-to-Site VPN connection entity that links the virtual network gateway and the local network gateway. The shared key serves as the pre-shared key that both sides use to authenticate during IPsec handshake, and it must match on the on-premises device. This resource is what actually creates and manages the encrypted tunnel between the two gateways.

  • ✗

    An ExpressRoute circuit.

    Why it's wrong here

    An ExpressRoute circuit is an entirely different connectivity service that provides a private, dedicated connection to Azure via a carrier or exchange provider, bypassing the public internet. It does not require an IPsec tunnel, a pre-shared key, or a local network gateway, and it is an alternative to VPN rather than a component that supports it. Therefore, it is not one of the three required components for a secure hybrid network built with Site-to-Site VPN.

  • ✓

    A virtual network gateway in Azure.

    Why this is correct

    A virtual network gateway is the Azure-side VPN gateway that is deployed into a dedicated GatewaySubnet and holds the public IP address through which the IPsec tunnel is terminated. It supports the 'Vpn' gateway type and provides redundant tunnels for high availability. This gateway is essential because it is the Azure endpoint that establishes the secure connection to the on-premises VPN device.

  • ✗

    An Azure Firewall.

    Why it's wrong here

    Azure Firewall is an optional, stateful firewall service that filters and logs traffic between virtual networks and to the internet, and it can be placed in a hybrid architecture to enforce security policies. However, Site-to-Site VPN connectivity will function perfectly without it, because the IPsec tunnel is established by the virtual network gateway and the connection resource. Thus, while it adds security, it is not a required component of the VPN implementation.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.