AZ-700 exam dumps

AZ-700 practice question 138 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 138

Select 2

You have an existing Azure ExpressRoute circuit with private peering for your on-premises environment. You need to connect a newly created Azure Virtual Network (VNet) in the same subscription to this existing circuit so that the new VNet� resources can communicate with on-premises servers over the ExpressRoute connection. Which two actions should you perform to establish this connectivity?

  1. A

    Create a Virtual Network Gateway in the new VNet with the ExpressRoute gateway type and associate it with the gateway subnet.

  2. B

    Configure inbound and outbound security rules on the Network Security Group (NSG) in the VNet to allow ExpressRoute traffic on TCP port 443.

  3. C

    Use the authorization key from the existing ExpressRoute circuit to create a VNet-to-ExpressRoute link for the new VNet.

  4. D

    Enable Microsoft peering on the existing ExpressRoute circuit and update BGP routes to reflect the new address ranges.

  5. E

    Enable NAT Gateway on the VNet to allow inbound and outbound traffic from on-premises over ExpressRoute.

Show answer and explanation

Correct answers: A, C

Explanation

Connecting a VNet to an existing ExpressRoute circuit typically involves creating an ExpressRoute-type Virtual Network Gateway in the new VNet and using the existing circuit� authorization key to link the VNet to the circuit. These steps follow best practices documented by Microsoft in 'Link a virtual network to an ExpressRoute circuit using the Azure portal' (https://learn.microsoft.com/azure/expressroute/howto-linkvnet-portal).

  • A. Correct.

    Option 1 is correct. To connect a VNet to an ExpressRoute circuit, you must create an ExpressRoute-type Virtual Network Gateway and place it in a dedicated gateway subnet. This gateway is then linked to your ExpressRoute circuit to enable private connectivity.

  • B. Incorrect.

    Option 2 is incorrect. Network Security Groups (NSGs) control traffic to and from resources in a subnet or network interface, but creating or changing NSG rules for port 443 is not a primary step for establishing ExpressRoute connectivity. By default, the gateway creation process will handle required routes and connections for the ExpressRoute tunnel itself.

  • C. Correct.

    Option 3 is correct. Once the Virtual Network Gateway is created, you need to use the authorization key (authorized circuit) from the existing ExpressRoute circuit to link the new VNet to that circuit. This step ensures the new VNet is allowed to connect to the circuit, enabling private peering for on-premises connectivity.

  • D. Incorrect.

    Option 4 is incorrect. Private peering, not Microsoft peering, is typically used to route traffic between on-premises networks and your Azure VNets. Microsoft peering is for accessing Microsoft SaaS services (e.g., Office 365). Since private peering is already configured and working, enabling Microsoft peering does not establish a private connection to the new VNet.

  • E. Incorrect.

    Option 5 is incorrect. A NAT Gateway is not required for ExpressRoute connectivity. NAT Gateway is used primarily for outbound internet traffic scenarios, not for private communications over ExpressRoute.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam