AZ-700 exam dumps

AZ-700 practice question 104 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 104

Single answer

Your company needs to establish a secure site-to-site VPN connection to Azure from an on-premises firewall that only supports policy-based IPsec VPN. However, your network team is also planning to implement dynamic routing (using BGP) in the near future. Which Azure VPN Gateway configuration should you choose to accommodate both the current firewall limitations and future routing requirements?

  1. A

    Use a Policy-based (Basic) Azure VPN gateway to match the on-premises firewall� policy-based configuration

  2. B

    Deploy an ExpressRoute circuit for private connectivity and dynamic routing

  3. C

    Implement a Route-based VPN gateway in Azure with policy-based traffic selectors

  4. D

    Implement a Route-based VPN gateway in Azure with active-active configuration

Show answer and explanation

Correct answer: C

Explanation

Azure supports two main VPN gateway types: Policy-based and Route-based. Policy-based gateways rely on static IPsec tunnels and lack support for dynamic routing. Route-based gateways use tunnel interfaces for IPsec encryption and can support advanced routing features like BGP. However, you can configure a Route-based gateway to accept policy-based traffic from older devices by enabling policy-based traffic selectors. This design meets the immediate requirement (compatibility with a policy-based firewall) while preserving the flexibility to implement BGP-based dynamic routing in the future. For more details, refer to Microsoft Azure documentation on 'About VPN Gateway' and 'VPN Policy-Based versus Route-Based' sections.

  • A. Incorrect.

    Incorrect. While a Policy-based (Basic) gateway is compatible with an older firewall that only supports policy-based VPN, it does not support future dynamic routing via BGP. This approach would force you to upgrade the gateway to route-based later.

  • B. Incorrect.

    Incorrect. ExpressRoute provides private, high-throughput connectivity, but it is not an IPsec-based VPN solution and does not address the immediate requirement of connecting a policy-based firewall over a VPN tunnel. It also entails higher costs and different provisioning steps.

  • C. Correct.

    Correct. A Route-based VPN gateway with policy-based traffic selectors can support the older firewall� policy-based IPsec now and accommodate dynamic routing (BGP) in the future without requiring a gateway replacement. This approach offers maximum flexibility for upcoming routing needs.

  • D. Incorrect.

    Incorrect. Although a route-based VPN with active-active configuration offers higher availability pathways, it does not specifically address the compatibility requirements of a policy-based firewall. Active-active alone does not solve the policy-based compatibility challenge.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam