Soru

Zorluk: Çok zorAzure Virtual Networks, ExpressRoute, and VPN Gateway

A multinational corporation is planning to connect its local infrastructure to resources inside an Azure Virtual Network. The network architect must satisfy the following three connectivity requirements:

1. The primary on-premises datacenter requires a private, high-bandwidth connection of 10 Gbps10\text{ Gbps} that bypasses the public internet entirely.
2. A remote branch office requires a secure, encrypted connection to Azure over the public internet on a limited budget.
3. Remote employees working from home must be able to securely connect their individual laptops directly to the Azure Virtual Network over the internet without requiring any on-premises hardware.

Which combination of Azure connectivity services should the company implement?

  1. An Azure ExpressRoute connection for the datacenter, a Site-to-Site VPN connection for the remote branch office, and a Point-to-Site VPN connection for the remote employees.Cevap
  2. B
    A Site-to-Site VPN connection for the datacenter, an Azure ExpressRoute connection for the remote branch office, and a Point-to-Site VPN connection for the remote employees.
  3. C
    An Azure ExpressRoute connection routing traffic over the public internet for the datacenter, a Site-to-Site VPN connection for the remote branch office, and a Point-to-Site VPN connection for the remote employees.
  4. D
    An Azure Virtual Network Peering connection for the datacenter, a Site-to-Site VPN connection for the remote branch office, and an Azure Bastion connection for the remote employees.

Cevap

An Azure ExpressRoute connection for the datacenter, a Site-to-Site VPN connection for the remote branch office, and a Point-to-Site VPN connection for the remote employees.
The combination featuring an Azure ExpressRoute connection for the datacenter, a Site-to-Site VPN connection for the remote branch office, and a Point-to-Site VPN connection for the remote employees is correct. ExpressRoute meets the datacenter's need for a private connection bypassing the public internet. Site-to-Site VPN provides a cost-effective encrypted tunnel over the internet for the branch office. Point-to-Site VPN allows individual remote laptops to securely connect directly to the virtual network without any specialized hardware on-premises.

Adım Adım Çözüm

1
Analyze the requirement for the primary datacenter connection.
Azure ExpressRoute is identified as the correct service because it provides a dedicated, private connection that bypasses the public internet entirely, supporting high bandwidth up to 100 Gbps100\text{ Gbps}.
Site-to-Site VPN routes traffic over the public internet and does not meet the requirement to bypass the internet.
2
Analyze the requirement for the remote branch office.
Site-to-Site VPN is selected because it provides a secure, encrypted (IPsec) connection over the public internet, which is cost-effective and suitable for a branch office.
An ExpressRoute circuit would be too expensive and complex for a remote branch office on a limited budget.
3
Analyze the requirement for the remote employees.
Point-to-Site VPN is selected because it enables secure connections directly from individual client devices (laptops) over the internet to the Azure Virtual Network, without requiring any on-premises VPN hardware.
Azure Bastion is for secure RDP/SSH access to VMs via a browser, not for general hybrid network connectivity from remote client laptops.

Anahtar Kavram

Azure hybrid networking options differ in privacy, bandwidth, cost, and target client configuration.
Bu soruyu puanla