exam questions

Exam AZ-300 All Questions

View all questions & answers for the AZ-300 exam

Exam AZ-300 topic 16 question 13 discussion

Actual exam question from Microsoft's AZ-300
Question #: 13
Topic #: 16
[All AZ-300 Questions]

You have an Azure subscription named Subscription1 that contains an Azure virtual network named VNet1. VNet1 connects to your on-premises network by using
Azure ExpressRoute.
You need to connect VNet1 to the on-premises network by using a site-to-site VPN. The solution must minimize cost.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Create a VPN gateway that uses the VpnGw1 SKU.
  • B. Create a connection.
  • C. Create a local site VPN gateway.
  • D. Create a gateway subnet.
  • E. Create a VPN gateway that uses the Basic SKU.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
References:
https://docs.microsoft.com/en-za/archive/blogs/canitpro/step-by-step-configuring-a-site-to-site-vpn-gateway-between-azure-and-on-premise

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AnujD
Highly Voted 5 years ago
A. Create a VPN gateway that uses the VpnGw1 SKU. B. Create a connection. C. Create a local site VPN gateway. We need to Gateway subnet also but since already Vnet1 is connecting to OnPrem via ExpressRoute so gateway subnet would already be existing. My answer is ABC
upvoted 45 times
jcarlos
5 years ago
i would say you are right. Only thing is that C Create a local site VPN gateway should be Create "local network gateway". https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager
upvoted 4 times
tartar
4 years, 8 months ago
ABC is ok
upvoted 1 times
...
...
Ramanraghav
4 years, 12 months ago
Why not VPN with basic SKU?
upvoted 1 times
...
cacasodo
4 years, 12 months ago
More info on VPN gateway SKUs: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways
upvoted 2 times
...
petermogaka91
4 years, 12 months ago
why not E? you can create a vpn with basic sku since the question mentions cost should be minimized https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways
upvoted 3 times
...
...
[Removed]
Highly Voted 4 years, 10 months ago
Possible answers: A. Create a VPN gateway that uses the VpnGw1 SKU. B. Create a connection. C. Create a local site VPN gateway. D. Create a gateway subnet. E. Create a VPN gateway that uses the Basic SKU. So that ExpressRoute and a Site-To-Site VPN can co-exists we can't use the Basic SKUs and therefor need to choose the "VpnGw1" SKU. Quote: "Basic SKU gateway is not supported. You must use a non-Basic SKU gateway for both the ExpressRoute gateway and the VPN gateway." Source: https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager This means A. and not E. Also we need a gateway subnet for sure (with a subnet mask of /27 or shorter prefix, such as /26 or /25). So D. is correct as well. According to this https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager#new (see Step 5.) we also need to create a "local site VPN gateway". This leads us to => A. C. and D.
upvoted 7 times
gboyega
4 years, 10 months ago
D is wrong because Expressroute and VPN gateway can co-exist. So they have the same gateway subnet no need to create another Answer is E. Create a VPN GATEWAY ( reduced cost than VPNGW1) C create a local vpn gateway B create a connection B C E
upvoted 4 times
andyR
4 years, 6 months ago
A is req'd to coexist with express route
upvoted 1 times
...
...
...
GvWaesberghe
Most Recent 4 years, 8 months ago
I think the correct answer would be ABC See https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager. Basic SKU gateway is not supported. You must use a non-Basic SKU gateway for both the ExpressRoute gateway and the VPN gateway.
upvoted 2 times
...
BEB
4 years, 9 months ago
VPN Gateway and Expressroute GW can coexist in the same Gateway Subnet (for failover for example). We already have Vnet, GWSubnet, and Express route. If we assume we are using the existing resources for VPN, we would move to use existing subnet, configure the LNG,(GwPIP), Virtual Network Gateway- type VPN (which is same as VPN GW), and a connection answer should be: • A. Create a VPN gateway that uses the VpnGw1 SKU. (assume we are using VPN and Express route on same gateway subnet) • B. Create a connection. (assume the question Local VPN decide is ready for connection) • C. Create a local site VPN gateway. (this should be same as Local Network GW specifying information for Local site VPN to which connection will be established)
upvoted 1 times
...
macco455
4 years, 9 months ago
The only issue I see with not creating a new gateway subnet is that it is not specifically stated what the CIDR is for the current one. We can guess they went by MS best practices and used a /27 which would be sufficient for the expressroute and S2S VPN to coexist on. SO the test questions would add that important piece of info to it I would imagine. Just something to think about.
upvoted 1 times
...
Qudzie
4 years, 9 months ago
I think the correct answer is ABC https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager check on the limitations.
upvoted 1 times
...
dpinlaguna
4 years, 9 months ago
A, C, D https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager
upvoted 3 times
...
WynterTsai
4 years, 10 months ago
I will go for ABC as well because gateway subnet already exists and we need the VpnGw1 SKU to support the express route.
upvoted 1 times
...
babablackship
4 years, 10 months ago
Create a gateway subnet. Create a VPN gateway that uses the Basic SKU. Create a connection. References: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resource-manager-portal
upvoted 2 times
...
jonnybugaloo
4 years, 10 months ago
Correcting my previous post: Answer is A B and C The question doesn't specify how much S2S tunnels or Throughput is needed, just specify about costs, but we have to pay attention about the express route, which uses BGP. BGP routes are only supported from VpnGw1 SKU. Also, since it's to minimize costs, we can consider using the same network subnet gateway already in use. The answer is A, B and C From the options offered: Create a VPN Gateway that uses VpnGw1 SKU - A (Supports BGP, requirement for VPN over Express Route circuits) Create a local site VPN gateway - C Create a VPN Connection - Site to site - B https://docs.microsoft.com/en-za/archive/blogs/canitpro/step-by-step-configuring-a-site-to-site-vpn-gateway-between-azure-and-on-premise https://docs.microsoft.com/pt-br/azure/vpn-gateway/vpn-gateway-about-vpngateways#gateway-skus https://docs.microsoft.com/pt-br/azure/expressroute/expressroute-howto-linkvnet-arm https://docs.microsoft.com/pt-br/azure/expressroute/site-to-site-vpn-over-microsoft-peering
upvoted 5 times
...
jonnybugaloo
4 years, 10 months ago
The question doesn't specify how much S2S tunnels or Throughput is needed, just specify about costs, but we have to pay attention about the express route, which uses BGP. BGP routes are only supported from VpnGw1 SKU. Also, since it's to minimize costs, we can consider using the same network subnet gateway already in use. The answer is A, D and E From the options offered: Create a VPN Gateway that uses VpnGw1 SKU - A (Supports BGP, requirement for VPN over Express Route circuits) Create a local site VPN gateway - C Create a VPN Connection - Site to site - B VPN Gateway basics supports Site to site or vnet to vnet conections up to 10 tunnels https://docs.microsoft.com/en-za/archive/blogs/canitpro/step-by-step-configuring-a-site-to-site-vpn-gateway-between-azure-and-on-premise https://docs.microsoft.com/pt-br/azure/vpn-gateway/vpn-gateway-about-vpngateways#gateway-skus https://docs.microsoft.com/pt-br/azure/expressroute/expressroute-howto-linkvnet-arm https://docs.microsoft.com/pt-br/azure/expressroute/site-to-site-vpn-over-microsoft-peering
upvoted 1 times
...
denkes
4 years, 10 months ago
See also here: https://www.examtopics.com/discussions/microsoft/view/4580-exam-az-103-topic-11-question-8-discussion/ https://www.examtopics.com/discussions/microsoft/view/15903-exam-az-103-topic-4-question-9-discussion/
upvoted 1 times
...
P0d
4 years, 11 months ago
If Express Route was installed then it means we have already Gateway and Gateway subnet on VNET it's connected. So as it's basic VNET GW, for S2S connection we need VPNGW SKU, then we will need to create A:VPNGW sku, then C: Local gateway network and create a B: connection. So answer will be ABC
upvoted 3 times
...
Gjferweb
4 years, 11 months ago
my answers is BCE (Basic GTW to minimize costs). GTW subnet must exist because of expressroute
upvoted 2 times
gboyega
4 years, 10 months ago
You are very correct B C E is the right answer
upvoted 4 times
admins
4 years, 8 months ago
No you are very much incorrect because a Standard VPN Gateway is required to coexist with an ExpressRoute. https://docs.microsoft.com/en-us/azure/expressroute/expressroute-howto-coexist-resource-manager
upvoted 2 times
...
...
...
Russel
4 years, 11 months ago
AnujD s correct.answer is A,B,C. D is not correct as Express route and VPN GW will use same Gateway subnet. Basic SQU doesnt support Express route and VPN Gw coexistence
upvoted 6 times
cacasodo
4 years, 11 months ago
Good point, Russel. Confirming information about the Basic SKU (legacy) limitations is here: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-skus-legacy
upvoted 1 times
...
...
Jetmahanakorn
5 years ago
A, C, D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago