AZ-500 exam dumps

AZ-500 practice question 65 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 65

Select 2

Your organization has established an ExpressRoute private peering connection to handle large volumes of sensitive financial transactions between on-premises data centers and Azure. To ensure the highest level of data protection, you decide to implement encryption over this ExpressRoute circuit. Which of the following approaches can be used to encrypt data in transit across the ExpressRoute private peering path? (Select TWO.)

  1. A

    Create an IPsec site-to-site VPN tunnel running on top of the existing ExpressRoute connection

  2. B

    Deploy Azure Key Vault to generate and store encryption keys for the ExpressRoute private peering path

  3. C

    Enable MACsec encryption on a supported ExpressRoute Direct circuit

  4. D

    Rely on the inherent encryption provided by the private nature of ExpressRoute

Show answer and explanation

Correct answers: A, C

Explanation

ExpressRoute provides private connectivity between on-premises networks and Azure, but it does not automatically encrypt traffic. You can achieve encryption by tunneling IPsec over the ExpressRoute circuit, or, for supported ExpressRoute Direct scenarios, enabling MACsec at Layer 2. Refer to Microsoft documentation on 'Encryption over ExpressRoute' for detailed guidance and best practices.

  • A. Correct.

    Option 1 is correct. Using an IPsec site-to-site VPN tunnel over the underlying ExpressRoute circuit can secure traffic in transit. The dedicated circuit by itself does not provide encryption, so layering IPsec is a valid approach.

  • B. Incorrect.

    Option 2 is incorrect. While Azure Key Vault securely stores and manages keys, it does not itself provide an in-transit encryption mechanism for ExpressRoute traffic. Key Vault is useful for secrets management but does not directly encrypt the data path.

  • C. Correct.

    Option 3 is correct. MACsec is a layer 2 encryption capability available on supported ExpressRoute Direct circuits (e.g., 10 Gbps or 100 Gbps). When enabled, it encrypts traffic crossing the provider’s shared infrastructure segments.

  • D. Incorrect.

    Option 4 is incorrect. ExpressRoute offers private connectivity, but private does not necessarily mean encrypted. By default, traffic is not encrypted unless you implement a specific encryption mechanism like IPsec or MACsec.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam