SC-100 Design security solutions for infrastructure Practice Question
You are designing a secure hybrid network connectivity solution between an on-premises datacenter and Azure. The requirement is to have encrypted traffic and high availability. Which service should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure VPN Gateway
Azure VPN Gateway (option C) is correct because it establishes encrypted IPsec/IKE site-to-site tunnels between on-premises networks and Azure, and it supports high availability through active-active configurations, multiple gateway instances, and zone-redundant SKUs. This directly satisfies the stated requirements of encrypted traffic and high availability for hybrid connectivity. Azure ExpressRoute (option B) provides private, dedicated connectivity but does not natively encrypt traffic over the circuit, so it does not meet the encryption requirement by itself. Azure Front Door (option A) is a global HTTP/HTTPS application delivery and load-balancing service, not a hybrid network tunnel, and Azure Bastion (option D) provides secure RDP/SSH access to VMs over the Azure portal without exposing public IPs, not site-to-site hybrid connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Front Door
Why it's wrong here
Azure Front Door operates at Layer 7 (HTTP/S) and is designed for global load balancing, SSL termination, and application acceleration. It does not create an encrypted tunnel between on-premises networks and Azure, nor does it provide routing of IP packets at the network layer. Therefore, it cannot serve as a site-to-site or point-to-site VPN solution for hybrid connectivity.
- ✗
Azure ExpressRoute
Why it's wrong here
Azure ExpressRoute provides a private, dedicated connection to Azure that bypasses the public internet, but it does not natively encrypt the data in transit. To achieve confidentiality, you must layer an encryption protocol (such as IPsec) over the ExpressRoute circuit, which adds complexity and does not meet the requirement for inherently encrypted hybrid connectivity. Without that extra layer, ExpressRoute alone is susceptible to inspection by the carrier and does not provide end-to-end encryption.
- ✓
Azure VPN Gateway
Why this is correct
Azure VPN Gateway is the correct choice because it natively supports site-to-site IPsec/IKE tunnels, which encrypt all traffic traversing the public internet between your on-premises network and Azure. It supports active-active configuration for high availability and failover, ensuring resilient encrypted connectivity. This meets the requirement for secure hybrid network connectivity without additional encryption layers or a dedicated private circuit.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion provides managed, secure RDP and SSH access to virtual machines directly through the Azure portal, using TLS for the session. It is designed for remote administration of individual VMs, not for connecting two networks together. Bastion does not establish a site-to-site VPN tunnel or route traffic between on-premises infrastructure and Azure VNet, so it is irrelevant to hybrid network connectivity.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.