Tailwind Traders needs a zone-redundant VPN Gateway deployed in a region that supports Availability Zones. Which of the following steps is required to implement a zone-redundant VPN gateway (example VpnGw2AZ) and ensure it remains highly available across zones?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy the VPN gateway using the VpnGw2AZ SKU in the gateway subnet. Provision a Standard SKU Public IP (zone-redundant) or zone placement as supported by the region. Ensure the region supports Availability Zones and do not pin the gateway to a single zone..
Why this is the answer
To deploy a zone-redundant VPN Gateway, you must select a VPN Gateway SKU that supports zone redundancy, such as VpnGw2AZ. This SKU automatically distributes gateway instances across Availability Zones within a region. A Standard SKU Public IP address is required because Basic SKU Public IPs do not support Availability Zones. The Public IP should also be zone-redundant or zone-placed if the region supports it. Crucially, you must not pin the gateway to a single zone during deployment; allowing Azure to distribute it ensures high availability across zones. Incorrect options: Deploying two separate VpnGw2 gateways in different VNets and using Azure Route Server creates a complex, multi-VNet setup, not a single zone-redundant gateway within one VNet. Manually creating two public IP addresses in different zones and trying to bind them to a VpnGw2 gateway is not how zone redundancy is configured for Azure VPN Gateways. The AZ SKU handles this automatically. There is no 'Availability Zone' toggle to convert a non-AZ VpnGw2 SKU to zone-redundant; zone redundancy is determined by the SKU chosen at deployment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed