Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Contoso recently provisioned an ExpressRoute Direct 10-Gbps port pair between its on-premises routers and Microsoft's edge. A new compliance mandate requires encrypting all traffic on the private circuit with the least possible latency while staying at Layer 2 (no tunnelling). What should you implement to meet the requirement?
Enable Azure Private Link for all workload endpoints that traverse the ExpressRoute circuit.
Enable MACsec on the ExpressRoute Direct ports and configure matching MKA pre-shared keys on the on-premises edge routers.
Enable IPsec encryption for Azure private peering by attaching an Azure VPN gateway to the ExpressRoute circuit.
Deploy Azure Firewall Premium in a secured virtual hub and turn on TLS inspection for outbound flows.
MACsec supplies IEEE 802.1AE link-layer encryption between your routers and Microsoft's edge ports when you use ExpressRoute Direct. Because encryption occurs in hardware at Layer 2, it adds only a few microseconds of latency while protecting every Ethernet frame once configured. IPsec over ExpressRoute uses a VPN gateway, operates at Layer 3, and introduces encapsulation overhead. Azure Firewall Premium's TLS inspection and Azure Private Link do not encrypt the wire traffic on the circuit.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is MACsec and how does it work in Azure ExpressRoute Direct?
Open an interactive chat with Bash
Why is IPsec encryption not suitable for this scenario?
Open an interactive chat with Bash
What role does Azure Private Link play in securing workloads, and why wasn’t it chosen here?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .