Your organization has five offices, each with a local internet connection and a firewall device. The offices currently connect through a third-party SD-WAN. In Azure you have VNet1 with a virtual network gateway (Gateway1), and each office connects to Gateway1 via Site-to-Site VPN. You need to replace the third-party SD-WAN with Azure Virtual WAN. Which action should you include in the migration plan?
Choose an answer
Tap an option to check your answer.
Correct answer: Delete Gateway1..
Why this is the answer
The correct action is to delete Gateway1. Azure Virtual WAN uses a hub-and-spoke architecture where the Virtual WAN hub acts as the central point for connectivity. When migrating to Virtual WAN, existing VPN gateways (like Gateway1) are replaced by the Virtual WAN hub's built-in VPN gateway functionality. You would connect your on-premises firewalls directly to the Virtual WAN hub. Creating new Point-to-Site (P2S) VPN connections is incorrect because P2S VPNs are for individual client connections, not site-to-site office connectivity. Creating an Azure Traffic Manager profile is irrelevant as Traffic Manager is a DNS-based traffic load balancer, not a networking service for site-to-site connectivity. Enabling active-active mode on Gateway1 is incorrect because Gateway1 will be replaced, not reconfigured.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed