You are designing connectivity so Azure Virtual Desktop session hosts in a spoke virtual network can access on‑premises file servers and license servers over private IPs with predictable latency and an SLA. Which two options meet the requirement? (Select two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: Implement ExpressRoute with private peering to the hub virtual network and propagate routes to the session host subnets., Implement site‑to‑site VPN with BGP to the hub virtual network and advertise corporate prefixes to Azure..
Why this is the answer
Both ExpressRoute with private peering and a site-to-site VPN with BGP are valid solutions for connecting Azure Virtual Desktop session hosts to on-premises resources with predictable latency and an SLA. ExpressRoute offers a dedicated private connection, ensuring high bandwidth and low latency, and private peering allows access to Azure resources over the private network. Site-to-site VPNs create an encrypted tunnel over the internet, and with BGP, dynamic routing ensures efficient traffic flow and high availability. Both options integrate with a hub virtual network, allowing routes to be propagated to spoke subnets where session hosts reside. ExpressRoute public peering is incorrect because it's designed for connecting to Microsoft 365 and Azure public services, not for accessing private on-premises resources. Point-to-site VPNs are for individual client connections, not for connecting entire subnets of session hosts, and would not scale or provide the required SLA. Publishing resources via Application Gateway is for web application delivery and doesn't provide the necessary private network connectivity for file and license servers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed