Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company uses a 5-Gbps ExpressRoute circuit with private peering to connect its on-premises datacenter to VNet1 in Azure. The circuit is provisioned through a service provider; ExpressRoute Direct is not in use. The security team now requires that all traffic over the circuit be encrypted in transit. You must meet the requirement while preserving the existing MPLS path and making the fewest topology changes. What should you recommend?
Deploy a route-based Azure VPN gateway in VNet1 and establish an IPsec site-to-site VPN that uses the ExpressRoute private peering.
Enable Azure Private Link for all workloads hosted in VNet1.
Replace the circuit with an Azure Virtual WAN secured virtual hub and connect the datacenter by using IPsec VPN.
Enable MACsec on the existing ExpressRoute circuit.
Traffic on a standard ExpressRoute private peering is not encrypted by default. Because the circuit is not ExpressRoute Direct, link-level MACsec cannot be enabled. Azure Private Link provides private addressing but does not add encryption, and replacing the architecture with Virtual WAN would introduce substantial changes. The supported way to add encryption with minimal change is to overlay an IPsec tunnel on the existing circuit by deploying a route-based Azure VPN gateway in VNet1 and configuring a site-to-site VPN that rides across the ExpressRoute private peering. This encrypts all traffic end-to-end while retaining the same physical path.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ExpressRoute in Azure, and how does it differ from a traditional VPN?
Open an interactive chat with Bash
What is an IPsec site-to-site VPN, and why is it needed in this solution?
Open an interactive chat with Bash
What is Azure Private Link, and why doesn’t it meet the encryption requirement here?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .