Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage an Azure route-based VPN gateway (VpnGw2 SKU) connected to an on-premises hardware VPN device. Governance mandates IPsec/IKE Phase 2 integrity as SHA256, encryption as AES256, and Diffie-Hellman Group 14. You must enforce these parameters from Azure without disrupting the existing tunnel. What should you do first?

  • Change the gateway to active-active mode and re-establish the tunnel.

  • Create and apply a custom IPsec/IKE policy on the current site-to-site VPN connection.

  • Enable policy-based traffic selectors on the VPN connection.

  • Convert the connection to ExpressRoute for private connectivity.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot