Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage a 10-Gbps ExpressRoute Direct circuit that carries both private and Microsoft peering traffic between your on-premises datacenter and multiple Azure virtual networks. A new compliance rule requires that every frame traversing the physical circuit be encrypted, but the networking team does not want to deploy additional VPN gateways or change existing routing. Which feature should you use to satisfy the requirement?
Attach an Azure VPN gateway to the circuit and enable IPsec encryption.
Configure every Azure workload to require TLS 1.2 connections.
Enable MACsec on the ExpressRoute Direct ports.
Turn on ExpressRoute FastPath for the virtual network connections.
Encryption at the physical circuit level for ExpressRoute Direct ports is achieved with Media Access Control Security (MACsec). MACsec provides Layer-2, wire-speed encryption between your routers and Microsoft's edge without changing IP routing, peering configurations, or adding VPN gateways. IPsec over ExpressRoute relies on virtual network gateways and therefore violates the "no additional gateways" constraint. Enabling TLS only secures individual application sessions, not all traffic on the circuit. ExpressRoute FastPath improves data-path performance by bypassing the gateway, but it does not add any form of encryption.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is MACsec and how does it work?
Open an interactive chat with Bash
How is MACsec different from IPsec?
Open an interactive chat with Bash
When should you use ExpressRoute FastPath, and how is it different from MACsec?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .