SC-100 Design security solutions for infrastructure Practice Question
Which THREE components are required to implement a secure hybrid network architecture using Azure VPN Gateway? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A local network gateway resource in Azure.
Option A (a local network gateway resource in Azure) is required because it defines the on-premises VPN device's public IP address and address spaces, which Azure uses as the remote endpoint for the site-to-site tunnel. Option B (a connection resource with a shared key) is required because the connection object links the virtual network gateway to the local network gateway and carries the pre-shared key (PSK) used for IKE/IPsec authentication. Option D (a virtual network gateway in Azure) is required because it is the Azure-side VPN Gateway (VpnGw SKU) that terminates the IPsec/IKE tunnel and routes traffic into the virtual network. Option C (an ExpressRoute circuit) does not belong because ExpressRoute is a private dedicated-circuit connectivity model, not a VPN Gateway component, and the scenario specifies VPN Gateway. Option E (an Azure Firewall) does not belong because it is a managed network security service for traffic filtering and is not a prerequisite for establishing a VPN Gateway site-to-site connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A local network gateway resource in Azure.
Why this is correct
The local network gateway is a logical Azure object that points to your on-premises VPN device by its public IP address and defines the on-premises address space(s) that Azure should advertise over the tunnel. Without it, the Azure virtual network gateway has no remote endpoint to establish an IPsec session with, nor any knowledge of which on-premises routes should be reachable. It is therefore a mandatory configuration item for a Site-to-Site VPN.
- ✓
A connection resource with a shared key.
Why this is correct
A connection resource with a shared key is the Site-to-Site VPN connection entity that links the virtual network gateway and the local network gateway. The shared key serves as the pre-shared key that both sides use to authenticate during IPsec handshake, and it must match on the on-premises device. This resource is what actually creates and manages the encrypted tunnel between the two gateways.
- ✗
An ExpressRoute circuit.
Why it's wrong here
An ExpressRoute circuit is an entirely different connectivity service that provides a private, dedicated connection to Azure via a carrier or exchange provider, bypassing the public internet. It does not require an IPsec tunnel, a pre-shared key, or a local network gateway, and it is an alternative to VPN rather than a component that supports it. Therefore, it is not one of the three required components for a secure hybrid network built with Site-to-Site VPN.
- ✓
A virtual network gateway in Azure.
Why this is correct
A virtual network gateway is the Azure-side VPN gateway that is deployed into a dedicated GatewaySubnet and holds the public IP address through which the IPsec tunnel is terminated. It supports the 'Vpn' gateway type and provides redundant tunnels for high availability. This gateway is essential because it is the Azure endpoint that establishes the secure connection to the on-premises VPN device.
- ✗
An Azure Firewall.
Why it's wrong here
Azure Firewall is an optional, stateful firewall service that filters and logs traffic between virtual networks and to the internet, and it can be placed in a hybrid architecture to enforce security policies. However, Site-to-Site VPN connectivity will function perfectly without it, because the IPsec tunnel is established by the virtual network gateway and the connection resource. Thus, while it adds security, it is not a required component of the VPN implementation.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.