You must expose an on-premises WCF SOAP service that uses NetTcpBinding and WS-Security to applications running in Azure. Inbound firewall ports on-premises cannot be opened. You need request-reply semantics and want to avoid a full site-to-site VPN. Which connectivity option should you choose?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Relay WCF Relay with NetTcp binding so the on-premises service connects outbound to Azure Relay..
Why this is the answer
Azure Relay WCF Relay with NetTcp binding is the correct choice because it specifically supports WCF services using NetTcpBinding and allows the on-premises service to make an outbound connection to Azure Relay, bypassing inbound firewall restrictions. This establishes a secure bidirectional communication channel without needing to open inbound ports or configure a full VPN. Request-reply semantics are inherently supported by WCF. Azure Relay Hybrid Connections use HTTP/WebSockets, which is not suitable for a NetTcpBinding WCF service. Azure VPN Gateway with site-to-site VPN is explicitly ruled out by the requirement to avoid a full site-to-site VPN. Azure Front Door Premium and Azure ExpressRoute private peering both require inbound connectivity to the on-premises network or a more complex network setup, which contradicts the constraint of not opening inbound firewall ports.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed