AZ-700 Question 152
Select 2You are designing an Azure Virtual WAN architecture for a global organization with multiple on-premises data centers across different continents. The company requires advanced routing between branch offices, traffic inspection for compliance, and centralized security management. They intend to use both site-to-site VPN and ExpressRoute connections, and also want the flexibility to integrate third-party Network Virtual Appliances (NVAs) in the future. Which TWO design approaches should you implement to meet these requirements?
- A
- Deploy a Basic Virtual WAN with multiple hubs and rely solely on site-to-site VPN for both connectivity and traffic inspection.
- B
- Use a Standard Virtual WAN with multi-hub deployment to enable ExpressRoute and site-to-site VPN connectivity, allowing for third-party NVA integration.
- C
- Implement Secure Virtual WAN using a Secure Virtual Hub for centralized traffic inspection and advanced routing, optionally integrating Azure Firewall or third-party NVAs.
- D
- Rely on a single Basic Virtual Hub in one region, and activate Azure Firewall for traffic inspection without enabling advanced routing.
Show answer and explanation
Correct answers: B, C
Explanation
To meet advanced routing, traffic inspection, and scalable connectivity needs across multiple sites, you'll typically adopt a Standard or Secure Virtual WAN architecture. Standard Virtual WAN hubs enable ExpressRoute and site-to-site VPN connectivity with flexible routing and the option for third-party NVAs, while Secure Virtual WAN (Secure Virtual Hub) extends these capabilities by providing a built-in security layer (including Azure Firewall) for traffic inspection. For more information, refer to Azure Virtual WAN documentation: https://learn.microsoft.com/azure/virtual-wan/virtual-wan-about.
- A. Incorrect.
Option 1: Incorrect. Basic Virtual WAN does not provide advanced routing, traffic inspection, or the flexibility to integrate third-party NVAs. This setup falls short of the advanced requirements for global connectivity and compliance.
- B. Correct.
Option 2: Correct. A Standard Virtual WAN supports site-to-site VPN, ExpressRoute, and the ability to connect third-party NVAs. It provides the advanced routing features necessary for large-scale environments and multiple locations.
- C. Correct.
Option 3: Correct. Secure Virtual WAN (with a Secure Virtual Hub) extends Standard Virtual WAN functionality by adding built-in security capabilities. It enables centralized traffic inspection with Azure Firewall or third-party NVAs, making it well-suited for compliance scenarios and robust security requirements.
- D. Incorrect.
Option 4: Incorrect. Using a single Basic Virtual Hub with Azure Firewall does not provide the advanced routing or integration flexibility needed for multinational connectivity. The Basic tier also lacks certain features that facilitate large-scale, multi-hub deployments.