Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an existing route-based VPN gateway that uses the VpnGw2 SKU and currently provides a site-to-site connection to your on-premises datacenter. The security team asks you to add point-to-site (P2S) remote access so that users authenticate with Azure Active Directory and perform multifactor authentication (MFA). In addition, the SSTP tunneling protocol must not be allowed. Which action should you perform on the VPN gateway to meet these requirements?
Downgrade the gateway to the Basic SKU and configure RADIUS authentication for P2S users.
Enable the OpenVPN protocol on the existing VpnGw2 gateway and configure Azure AD as the P2S authentication method.
Replace the route-based gateway with a policy-based VPN gateway and enable IKEv1 for P2S connections.
Configure Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) with user certificates and enforce MFA through Conditional Access.
Azure AD-based authentication for point-to-site VPN connections in Azure is only supported when the OpenVPN tunneling protocol is enabled on a route-based VPN gateway that uses a VpnGw1 or higher SKU. OpenVPN supports Azure AD tokens and allows Conditional Access policies such as MFA. SSTP is not compatible with Azure AD authentication, and certificate (EAP-TLS) or RADIUS methods do not satisfy the requirement of Azure AD-based MFA without additional infrastructure. A policy-based gateway cannot be used for OpenVPN or Azure AD authentication.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a route-based VPN gateway?
Open an interactive chat with Bash
Why is OpenVPN required for Azure AD-based authentication?
Open an interactive chat with Bash
What is the difference between route-based and policy-based VPN gateways?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .