SC-100 ExpressRoute Practice Question
You are designing a secure hybrid network for a multinational company. They require encrypted communication between on-premises data centers and Azure, with high availability and no single point of failure. Which solution should you recommend?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy ExpressRoute with a site-to-site VPN as a failover.
Option A is correct because ExpressRoute provides a private, high-bandwidth dedicated connection to Azure, and pairing it with a site-to-site VPN failover ensures encrypted traffic and eliminates a single point of failure if the ExpressRoute circuit goes down. The VPN failover also satisfies the encryption requirement since ExpressRoute by itself does not encrypt data in transit. Option B provides encryption and redundancy but relies solely on internet-based VPN, which lacks the dedicated private connectivity and predictable performance of ExpressRoute. Option C is wrong because point-to-site VPN is designed for individual client devices, not data center-to-Azure connectivity. Option D is wrong because ExpressRoute without encryption does not meet the encrypted communication requirement, and relying only on Microsoft backbone security does not provide the required encryption or redundancy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy ExpressRoute with a site-to-site VPN as a failover.
Why this is correct
ExpressRoute offers a private, dedicated, and low-latency path from on-premises data centers to Azure, ensuring reliable connectivity that avoids the public internet. By pairing ExpressRoute with a site-to-site VPN as a failover, you add an encrypted tunnel over the internet or over the ExpressRoute circuit itself, satisfying both encryption and high-availability requirements. This hybrid approach provides a robust connection that meets strict enterprise security policies while maintaining business continuity during a primary circuit failure.
- ✗
Deploy a site-to-site VPN over the internet with two active VPN devices.
Why it's wrong here
A site-to-site VPN over the internet with two active VPN devices provides encryption and redundancy, but it lacks the dedicated, private connectivity that ExpressRoute offers. Public internet-based VPNs subject to variable latency, packet loss, and potential congestion, which is not ideal for a multinational company requiring consistent performance and strict SLAs. While it is a valid low-cost option, it fails to meet the need for a private, reliable backbone connection that is central to many enterprise compliance and performance mandates.
- ✗
Deploy Azure Virtual WAN with point-to-site VPN for each data center.
Why it's wrong here
Azure Virtual WAN with point-to-site (P2S) VPN is designed for individual remote clients, such as telecommuters, to connect securely to Azure. It does not provide site-to-site connectivity between on-premises data centers and Azure, and P2S tunnels lack the bandwidth and low-latency characteristics needed for interconnecting enterprise data centers. Additionally, each data center requiring a separate P2S connection would create management overhead and scalability issues, not a robust hybrid network solution.
- ✗
Deploy ExpressRoute without encryption and rely on Microsoft backbone security.
Why it's wrong here
ExpressRoute provides a dedicated, private connection to Azure but does not encrypt traffic by default. Relying on Microsoft's backbone security does not fulfill an explicit encryption requirement, as data traversing the ExpressRoute circuit can be intercepted at physical points or by unauthorized access to the network equipment. To achieve end-to-end encryption, a VPN over ExpressRoute or another encryption protocol is necessary, making this option technically inadequate.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.