AZ-700 exam dumps

AZ-700 practice question 157 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 157

Single answer

You manage a multi-site on-premises environment that needs to connect securely to an Azure Virtual WAN you have deployed in the East US region. You have already created a Virtual WAN and a Virtual Hub in East US. Now you want to set up a Site-to-Site VPN gateway within the Virtual WAN hub to connect your sites. Which approach should you use to deploy the gateway and configure your on-premises connections through the Azure portal?

  1. A

    Create a separate VPN gateway resource outside of the Virtual WAN, and then peer it with the Virtual WAN hub.

  2. B

    Within the Virtual WAN hub� properties, add a VPN site for each on-premises location and connect it to the VPN gateway in the Virtual Hub.

  3. C

    From the Virtual WAN overview blade, enable the �Auto Detect On-Premises Subnets� option under the VPN Gateway settings to create site connections.

  4. D

    Deploy a separate ExpressRoute gateway resource in the hub and enable Site-to-Site VPN on that gateway.

Show answer and explanation

Correct answer: B

Explanation

In Azure Virtual WAN, you add a VPN site for each on-premises location and associate that site with the VPN gateway in the Virtual Hub to establish Site-to-Site connectivity. This involves specifying the on-premises VPN endpoint IP address and gateway configuration. For more details, refer to Microsoft� documentation on creating and associating VPN sites in Virtual WAN: https://learn.microsoft.com/azure/virtual-wan/vpn-site-to-site-portal.

  • A. Incorrect.

    Option 1 is incorrect because creating a separate VPN gateway resource and peering it with the Virtual WAN hub is not how Site-to-Site VPN connectivity is configured in Azure Virtual WAN. The correct approach is to use the built-in VPN gateway capability in the Virtual Hub.

  • B. Correct.

    Option 2 is correct. You must define one or more VPN sites (representing on-premises locations) in the Virtual WAN and connect them to the built-in VPN gateway in the Virtual Hub. Each site configuration includes the on-premises VPN endpoint IP and other details. This is the proper method recommended by Azure documentation.

  • C. Incorrect.

    Option 3 is incorrect. Azure Virtual WAN does not have an �Auto Detect On-Premises Subnets� feature. You manually configure each VPN site and associate it with the hub� VPN gateway settings.

  • D. Incorrect.

    Option 4 is incorrect because deploying an ExpressRoute gateway does not provide Site-to-Site VPN connectivity. An ExpressRoute gateway is specifically for private peering to on-premises over ExpressRoute circuits, not for IPsec-based VPN connections.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam