AZ-700 exam dumps

AZ-700 practice question 158 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 158

Single answer

Your organization has created a Virtual WAN and a hub in the East US region to connect multiple branch offices via site-to-site VPN. The East US hub currently has no gateways deployed. You need to deploy a new VPN gateway in this existing East US hub and ensure on-premises sites can connect securely using non-overlapping address spaces. Which of the following actions must you take to successfully implement this gateway and establish connectivity from the on-premises sites?

  1. A

    Create a VPN gateway in the East US hub and define each on-premises location as a site resource linked to that gateway.

  2. B

    Deploy a separate ExpressRoute gateway first in the East US hub and then enable the site-to-site VPN feature within the same gateway.

  3. C

    Delete the existing Virtual WAN hub and recreate it with a VPN gateway from the start, as gateways cannot be added to an existing hub.

  4. D

    Configure forced tunneling on the on-premises routers and specify 0.0.0.0/0 as the only route, allowing the existing hub to auto-create the VPN gateway.

Show answer and explanation

Correct answer: A

Explanation

To deploy a site-to-site VPN gateway in an existing Azure Virtual WAN hub, you add a VPN gateway resource to the hub and define each on-premises network as a separate site resource. This approach ensures that your on-premises sites can securely connect to Azure via Virtual WAN, and it follows Microsoft documentation guidelines for Virtual WAN gateway deployments. Refer to the official Microsoft Azure Virtual WAN documentation for the recommended steps to configure VPN gateways and associate sites within a Virtual WAN hub.

  • A. Correct.

    Option 1 is correct. When adding a VPN gateway to an existing Virtual WAN hub, you must deploy the VPN gateway resource in that hub and define site resources for each on-premises location. These site definitions (including IP addresses and connection settings) are then associated with the gateway, enabling site-to-site connectivity. This is the recommended, straightforward method for adding a new VPN gateway to an existing Virtual WAN hub.

  • B. Incorrect.

    Option 2 is incorrect. ExpressRoute gateways are for dedicated private connections, not site-to-site VPN connectivity. While you can mix ExpressRoute and VPN gateways in the same Virtual WAN hub, there is no requirement to deploy ExpressRoute first to enable site-to-site VPN. They are separate gateway types with different purposes.

  • C. Incorrect.

    Option 3 is incorrect. You can add a gateway to an existing Virtual WAN hub without the need to delete and recreate the hub. Azure Virtual WAN supports adding or removing gateways independently as your connectivity needs change.

  • D. Incorrect.

    Option 4 is incorrect. Forced tunneling and 0.0.0.0/0 routes do not automatically create a VPN gateway in the hub. You must deliberately deploy a VPN gateway resource in the hub and configure sites. Merely setting forced tunneling on the on-premises routers does not cause the gateway to materialize in Azure.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam