AZ-700 exam dumps

AZ-700 practice question 82 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 82

Select 2

You are designing a site-to-site VPN connection for an organization that requires continuous availability between their on-premises data center and Azure. The organization wants to automatically fail over to a secondary connection in case the primary connection or on-premises VPN device fails. Which two design approaches should you recommend to achieve high availability for the site-to-site VPN?

  1. A

    Deploy an Active-Active VPN Gateway in Azure and configure BGP for dynamic routing.

  2. B

    Configure only a single tunnel from the on-premises environment to the Azure VPN Gateway using static routing.

  3. C

    Use an ExpressRoute circuit as the backup for the site-to-site VPN connection.

  4. D

    Set up two on-premises VPN devices in an HA cluster, each connecting to a separate public IP address on the Azure VPN Gateway.

Show answer and explanation

Correct answers: A, D

Explanation

For high availability in site-to-site VPNs, the recommended strategies include deploying an Azure VPN Gateway in Active-Active mode and using BGP for dynamic routing when possible. Additionally, on-premises redundancy typically involves two VPN devices in a high-availability or failover cluster configuration. These approaches remove single points of failure and allow for automatic rerouting if one device or tunnel fails. For more information, see the official Azure VPN Gateway documentation: https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-highlyavailable.

  • A. Correct.

    Option 1 is correct. By deploying an Active-Active VPN Gateway, you have two active tunnels, and using BGP allows for automatic path selection and failover if one tunnel or on-premises device fails. This setup provides high availability and dynamic routing.

  • B. Incorrect.

    Option 2 is incorrect. Using a single tunnel with static routing introduces a single point of failure. If that tunnel or the associated device goes down, you lose connectivity entirely.

  • C. Incorrect.

    Option 3 is incorrect. ExpressRoute is a separate service providing a private connection, not a direct backup for VPN in the traditional sense. While you can design a hybrid failover strategy using ExpressRoute, this option by itself is not a straightforward solution for site-to-site VPN redundancy to the same Azure environment.

  • D. Correct.

    Option 4 is correct. Having two on-premises VPN devices in an active/passive or clustered configuration that each connect to separate public IP addresses of the Azure VPN Gateway ensures that if one on-premises device fails, the other can seamlessly take over, maintaining availability.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam