AZ-500 exam dumps

AZ-500 practice question 64 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 64

Select 2

Your company has established a private connection to Azure using ExpressRoute. However, your InfoSec team requires all data traversing this connection to be encrypted in transit. Which two approaches could you implement to ensure your traffic is encrypted over ExpressRoute?

  1. A

    Set up an IPsec site-to-site VPN tunnel over the ExpressRoute circuit

  2. B

    Configure MACsec encryption if using ExpressRoute Direct and it is supported by both the provider and your on-premises device

  3. C

    Rely on the inherent encryption capabilities of ExpressRoute

  4. D

    Enable a built-in TLS toggle in the ExpressRoute portal for end-to-end encryption

Show answer and explanation

Correct answers: A, B

Explanation

ExpressRoute offers a private, dedicated connection to Azure but does not inherently encrypt traffic. To meet data-in-transit encryption requirements, you must layer encryption protocols such as IPsec or MACsec on top of ExpressRoute. Refer to Microsoft’s official documentation (https://learn.microsoft.com/azure/expressroute/expressroute-encryption) for best practices on securely implementing data encryption with ExpressRoute.

  • A. Correct.

    Correct. Deploying an IPsec VPN (site-to-site) tunnel in conjunction with ExpressRoute is a common method to provide end-to-end encryption for data in transit. You can configure an Azure VPN Gateway on the Azure side and a compatible IPsec endpoint on-premises.

  • B. Correct.

    Correct. MACsec (Media Access Control Security) can be implemented if you are using ExpressRoute Direct and your hardware supports it. MACsec encrypts Layer 2 LAN traffic and is supported in certain co-location scenarios and direct peering arrangements. This also ensures data confidentiality in transit.

  • C. Incorrect.

    Incorrect. ExpressRoute itself provides a private connection but does not include native encryption of traffic. You need an additional encryption mechanism (such as IPsec or MACsec) to encrypt the data in transit.

  • D. Incorrect.

    Incorrect. There is no simple toggle in the ExpressRoute portal to enable encryption for all traffic. While application-layer encryption (like TLS/SSL) can secure specific workloads, it does not solve encryption for all traffic at the network layer.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam