AZ-700 exam dumps

AZ-700 practice question 132 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 132

Select 2

Your company wants to securely connect its on-premises data center (using the 10.10.0.0/16 network) to an Azure VNet (using the 10.20.0.0/16 network) via ExpressRoute private peering. You have already created the ExpressRoute circuit and received the primary and secondary IP address pairs for BGP sessions. Which of the following configuration steps must be performed to allow traffic to flow between the on-prem network and the Azure VNet over private peering? (Choose two.)

  1. A

    Configure BGP sessions on the on-prem router using the IP addresses provided by Azure for private peering, ensuring 10.10.0.0/16 is advertised to Azure.

  2. B

    Advertise a default route (0.0.0.0/0) to Azure through the private peering to handle all outbound internet traffic from the on-premises network.

  3. C

    Assign the correct VLAN ID for private peering on both your local router and the ExpressRoute circuit, ensuring the VLAN used matches the one set during circuit provisioning.

  4. D

    Use overlapping IP address spaces (e.g., 10.10.0.0/16 in both the VNet and on-prem) to streamline routing across ExpressRoute private peering.

Show answer and explanation

Correct answers: A, C

Explanation

When configuring Azure private peering, you must establish BGP sessions on the correct VLAN ID, and each side should advertise unique, non-overlapping address spaces. See Microsoft� ExpressRoute documentation (https://learn.microsoft.com/azure/expressroute/about-expressroute-routing) for detailed guidance on setting up private peering, VLAN assignments, and route advertisements.

  • A. Correct.

    Correct. In Azure private peering, you must establish BGP sessions between your on-prem router and the Microsoft Edge routers. You advertise your on-premises address ranges (10.10.0.0/16) via BGP so Azure can route traffic back to on-prem. This is a key step in enabling network connectivity via ExpressRoute.

  • B. Incorrect.

    Incorrect. While it is possible to advertise a default route to Azure, it is not a requirement for private peering to function. In many designs, you selectively advertise only the necessary on-prem networks instead of default routes, especially if your on-prem network uses different paths to reach the internet.

  • C. Correct.

    Correct. During ExpressRoute setup, you specify a VLAN ID for private peering. You must configure this same VLAN ID on your on-prem router� interface connecting to the ExpressRoute circuit provider. This step ensures proper VLAN tagging and traffic steering for private peering.

  • D. Incorrect.

    Incorrect. Overlapping IP addresses between on-prem and Azure are not allowed for ExpressRoute private peering. The addresses for Azure VNets and on-prem networks must be unique to avoid routing conflicts.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam