Your on-premises Active Directory syncs with Microsoft Entra. You have an Azure virtual network VNet1 and will deploy an AVD host pool (Pool1) with session hosts joined to the on-premises AD domain. Which three networking resources should you include to provide connectivity between Azure and on-premises?
Choose an answer
Tap an option to check your answer.
Correct answer: a local network gateway, a Site-to-site (IPSec) connection type, a virtual network gateway.
Why this is the answer
To connect your Azure VNet1 to your on-premises Active Directory, you need a secure and reliable network connection. A virtual network gateway is deployed in Azure and provides the VPN endpoint for the Azure side of the connection. A local network gateway represents your on-premises VPN device and its public IP address to Azure. Finally, a Site-to-site (IPSec) connection type establishes the encrypted tunnel between the Azure virtual network gateway and your on-premises network, allowing the AVD session hosts to join the on-premises domain. A public load balancer is for distributing traffic to services, not for site-to-site connectivity. A VNet-to-VNet connection is for connecting two Azure VNets, not an Azure VNet to an on-premises network. Public IP addresses for every session host are unnecessary and expose them directly to the internet, which is a security risk and not how domain-joining works.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed