exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 1 question 13 discussion

Actual exam question from Microsoft's AZ-700
Question #: 13
Topic #: 1
[All AZ-700 Questions]

You have an Azure virtual network named Vnet1 and an on-premises network. The on-premises network has policy-based VPN devices.
In Vnet1, you deploy a virtual network gateway named GW1 that uses a SKU of VpnGw1 and is route-based.
You have a Site-to-Site VPN connection for GW1 as shown in the following exhibit.

You need to ensure that the on-premises network can connect to the route-based GW1.
What should you do before you create the connection?

  • A. Set Connection Mode to ResponderOnly.
  • B. Set BGP to Enabled.
  • C. Set Use Azure Private IP Address to Enabled.
  • D. Set IPsec / IKE policy to Custom.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RageshBethapudi
Highly Voted 2 years, 11 months ago
correct answer is D. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps
upvoted 16 times
...
jilguens
Highly Voted 2 years, 11 months ago
Selected Answer: D
D is correct
upvoted 5 times
...
620b351
Most Recent 10 months, 3 weeks ago
Selected Answer: D
Correct answerd is D. BGP is not mandatory to have a S2S VPN.
upvoted 1 times
...
vDreams
1 year, 11 months ago
correct answer is D. BGP will trade routes, not the algorithm to setup the VPN. Also, as per documentation (https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-bgp-overview#why) is an optional feature to use as Route-Based. https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-bgp-overview#why
upvoted 1 times
...
khanda
2 years, 4 months ago
Selected Answer: D
Correct answer is D
upvoted 1 times
...
Chezzer83
2 years, 4 months ago
Selected Answer: D
I assumed D for this. BGP is not required to configure a VPN connection.
upvoted 2 times
...
where2go
2 years, 4 months ago
Its D --- The configuration option is part of the custom IPsec/IKE connection policy. If you enable the policy-based traffic selector option, you must specify the complete policy (IPsec/IKE encryption and integrity algorithms, key strengths, and SA lifetimes). The configuration option is part of the custom IPsec/IKE connection policy. If you enable the policy-based traffic selector option, you must specify the complete policy (IPsec/IKE encryption and integrity algorithms, key strengths, and SA lifetimes).
upvoted 1 times
...
bennasu
2 years, 5 months ago
If you set the IPsec/IKE config to default, under most of the circumstances, azure VPN GW will automatically match the on prem Firewall's IPsec Phase 1 and phase 2 configuration(modern FW like fortigate,sonicwall). But if you are using cisco ASA then it's a different story. You would need to configure the phase manually
upvoted 1 times
...
Bbb78
2 years, 6 months ago
I am not sure any of the 4 answers are correct. Mainly because this is ENABLED - "Use policy based traffic selector " ...if the onPrem device(s) is route based then this is not needed ?
upvoted 1 times
...
sserna
2 years, 6 months ago
En examen 20/01/2023
upvoted 2 times
...
mm2
2 years, 7 months ago
Selected Answer: D
route-based also mean static routes and all others routing protocols, when policy based, based on configured networks that should be routed for this specific VPN. From network perspective route-based use ROUTING TABLE to make route decision, this includes all directly connected networks and mentioned static routes. Making an assumption that BGP=Route-based as a must - is wrong imho however you can configure route-based to communicated with multiple policy base devices. Please notice POLICY BASE DEVICES for on prem, not DEVICE [one], there are multiple in question.
upvoted 2 times
...
mm2
2 years, 7 months ago
route-based also mean static routes and all others routing protocols, when policy based, based on configured networks that should be routed for this specific VPN. From network perspective route-based use ROUTING TABLE to make route decision, this includes all directly connected networks and mentioned static routes. Making an assumption that BGP=Route-based as a must - is wrong imho.
upvoted 1 times
...
zukako
2 years, 7 months ago
Not have to set BGP if onpremise is act/stanby
upvoted 1 times
...
Andre369
2 years, 8 months ago
Selected Answer: D
correct answer is D. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps
upvoted 1 times
...
JRodJ
2 years, 8 months ago
I don't think any of these answers is correct. In order to talk to on premises there is another button that must be enabled not visible on this screenshot. Use custom traffic selectors and it needs to be enabled. I have verified this works by configuring it at my customer's location with 3 separate sites.
upvoted 1 times
...
Libaax01
2 years, 9 months ago
The correct answer is D, you can not have Policy based VPN one end and Route Based VPN on the other. Both ends need to match on the type of VPN being used.
upvoted 1 times
...
Prutser2
2 years, 10 months ago
Selected Answer: D
Previously, when working with policy-based VPNs, you were limited to using the policy-based VPN gateway Basic SKU and could only connect to 1 on-premises VPN/firewall device. Now, using custom IPsec/IKE policy, you can use a route-based VPN gateway and connect to multiple policy-based VPN/firewall devices. To make a policy-based VPN connection using a route-based VPN gateway, configure the route-based VPN gateway to use prefix-based traffic selectors with the option "PolicyBasedTrafficSelectors". as per https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...