You are planning a Site-to-Site VPN between your on-premises datacenter and an Azure virtual network. Which two resources should be included in your design to support the connection? Each correct answer is part of the solution. (NOTE: Each correct selection is worth one point.)
Choose an answer
Tap an option to check your answer.
Correct answer: a virtual network gateway.
Why this is the answer
A virtual network gateway is essential for establishing a Site-to-Site VPN connection in Azure. It acts as a VPN device within your Azure virtual network, allowing encrypted traffic to flow between your on-premises network and Azure. Without a virtual network gateway, there is no endpoint in Azure to terminate the VPN tunnel. User-defined routes (UDRs) might be used to direct traffic within Azure or to specific NVA appliances, but they don't establish the VPN tunnel itself. Azure Firewall and Azure Web Application Firewall (WAF) are security services that inspect and filter traffic, but they do not create the VPN connection. An on-premises data gateway is used for connecting on-premises data sources to Azure services like Power Apps or Logic Apps, not for network-level VPNs. An Azure application gateway is a Layer 7 load balancer and traffic manager for web applications, not a VPN gateway.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed