Soru

Zorluk: Çok zorAzure Virtual Networks, ExpressRoute, and VPN Gateway

An organization is designing a hybrid network architecture to connect their on-premises office to two Azure Virtual Networks (VNets). The design must meet the following criteria:

* A primary connection with dedicated, high-speed bandwidth that does not use the public internet.
* A secondary, encrypted backup connection that is cost-effective and routes over the public internet.
* Internal, low-latency communication directly between the two Azure VNets.

Which of the following Azure networking features should the organization implement to meet these requirements? (Select three)

  1. Azure ExpressRoute to establish the primary dedicated private connectionCevap
  2. A Site-to-Site VPN Gateway to establish the encrypted backup connection over the public internetCevap
  3. Virtual Network (VNet) peering to enable direct, low-latency communication between the two VNetsCevap
  4. D
    An ExpressRoute circuit configured to route primary traffic over the public internet using default IPSec encryption
  5. E
    A public cloud gateway to route all internal traffic between the two VNets through public on-premises endpoints

Cevap

To meet the specified criteria, the organization should implement Azure ExpressRoute for the primary private connection, a Site-to-Site VPN Gateway for the backup internet-based connection, and Virtual Network (VNet) peering for direct VNet-to-VNet connectivity.
The correct implementation involves three distinct services: Azure ExpressRoute fulfills the primary connection requirement by offering dedicated, private bandwidth that bypasses the public internet. A Site-to-Site VPN Gateway fulfills the backup connection requirement by encrypting traffic and routing it over the public internet in a cost-effective manner. Virtual Network (VNet) peering enables direct, low-latency connection between the two VNets using the private Microsoft backbone network.

Adım Adım Çözüm

1
Analyze the primary connection requirement.
Azure ExpressRoute must be selected because the requirement specifies a dedicated, high-speed path that bypasses the public internet.
ExpressRoute establishes a private connection via a service provider directly to the Azure backbone.
2
Analyze the backup connection requirement.
A Site-to-Site VPN Gateway must be selected because the requirement specifies a cost-effective, encrypted connection routing over the public internet.
VPN Gateway encrypts traffic and routes it through the public internet, which is less expensive than ExpressRoute.
3
Analyze the VNet-to-VNet communication requirement.
Virtual Network (VNet) peering must be selected to allow direct, low-latency communication.
VNet peering routes traffic through Microsoft's private network without traversing the on-premises datacenter or the public internet.

Anahtar Kavram

Azure hybrid networking components (ExpressRoute, VPN Gateway, and VNet peering) and their transmission medium (private backbone vs. public internet).
Bu soruyu puanla