Northwind Logistics wants automatic failover to a site‑to‑site VPN if their ExpressRoute circuit fails. They already have an S2S VPN gateway (route‑based) with BGP and an ExpressRoute circuit. Which configuration will provide fastest and most reliable failover while preserving route propagation to VNets?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure both ExpressRoute and the VPN with BGP, advertise the same on‑prem prefixes on both, and use BGP path attributes (on‑prem local preference or weight) to prefer ExpressRoute; when ExpressRoute fails BGP will withdraw routes and traffic will fail over to VPN..
Why this is the answer
The correct option leverages BGP's dynamic routing capabilities for fast and reliable failover. By advertising the same on-premises prefixes over both ExpressRoute and the S2S VPN and manipulating BGP path attributes (like local preference or weight on the on-premises router), ExpressRoute can be preferred. When ExpressRoute fails, BGP automatically withdraws its routes, causing Azure to instantly switch traffic to the available VPN path. This preserves route propagation to VNets. The other options are less efficient or reliable: configuring primary/backup in the Azure portal for gateways doesn't apply to ExpressRoute/VPN coexistence for failover; static UDRs require manual intervention and don't scale; VNet peering failover policies are not designed for this specific cross-premises failover scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed