Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a secure hybrid network connectivity solution between an on-premises datacenter and Azure. The requirement is to have encrypted traffic and high availability. Which service should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure VPN Gateway

Azure VPN Gateway (option C) is correct because it establishes encrypted IPsec/IKE site-to-site tunnels between on-premises networks and Azure, and it supports high availability through active-active configurations, multiple gateway instances, and zone-redundant SKUs. This directly satisfies the stated requirements of encrypted traffic and high availability for hybrid connectivity. Azure ExpressRoute (option B) provides private, dedicated connectivity but does not natively encrypt traffic over the circuit, so it does not meet the encryption requirement by itself. Azure Front Door (option A) is a global HTTP/HTTPS application delivery and load-balancing service, not a hybrid network tunnel, and Azure Bastion (option D) provides secure RDP/SSH access to VMs over the Azure portal without exposing public IPs, not site-to-site hybrid connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door operates at Layer 7 (HTTP/S) and is designed for global load balancing, SSL termination, and application acceleration. It does not create an encrypted tunnel between on-premises networks and Azure, nor does it provide routing of IP packets at the network layer. Therefore, it cannot serve as a site-to-site or point-to-site VPN solution for hybrid connectivity.

  • ✗

    Azure ExpressRoute

    Why it's wrong here

    Azure ExpressRoute provides a private, dedicated connection to Azure that bypasses the public internet, but it does not natively encrypt the data in transit. To achieve confidentiality, you must layer an encryption protocol (such as IPsec) over the ExpressRoute circuit, which adds complexity and does not meet the requirement for inherently encrypted hybrid connectivity. Without that extra layer, ExpressRoute alone is susceptible to inspection by the carrier and does not provide end-to-end encryption.

  • ✓

    Azure VPN Gateway

    Why this is correct

    Azure VPN Gateway is the correct choice because it natively supports site-to-site IPsec/IKE tunnels, which encrypt all traffic traversing the public internet between your on-premises network and Azure. It supports active-active configuration for high availability and failover, ensuring resilient encrypted connectivity. This meets the requirement for secure hybrid network connectivity without additional encryption layers or a dedicated private circuit.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion provides managed, secure RDP and SSH access to virtual machines directly through the Azure portal, using TLS for the session. It is designed for remote administration of individual VMs, not for connecting two networks together. Bastion does not establish a site-to-site VPN tunnel or route traffic between on-premises infrastructure and Azure VNet, so it is irrelevant to hybrid network connectivity.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.