exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 1 question 13 discussion

Actual exam question from Microsoft's AZ-700
Question #: 13
Topic #: 1
[All AZ-700 Questions]

You have an Azure virtual network named Vnet1 and an on-premises network. The on-premises network has policy-based VPN devices.
In Vnet1, you deploy a virtual network gateway named GW1 that uses a SKU of VpnGw1 and is route-based.
You have a Site-to-Site VPN connection for GW1 as shown in the following exhibit.

You need to ensure that the on-premises network can connect to the route-based GW1.
What should you do before you create the connection?

  • A. Set Connection Mode to ResponderOnly.
  • B. Set BGP to Enabled.
  • C. Set Use Azure Private IP Address to Enabled.
  • D. Set IPsec / IKE policy to Custom.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 1 month ago
D. Set IPsec / IKE policy to Custom. In order to ensure that the on-premises network can connect to the route-based virtual network gateway, you need to set the IPsec / IKE policy to Custom. The default policy settings for a virtual network gateway are not compatible with policy-based VPN devices. By setting the IPsec / IKE policy to Custom, you can configure the policy to match the requirements of the on-premises VPN devices. Option A, "Set Connection Mode to ResponderOnly," is not a valid option for a route-based VPN gateway. Option B, "Set BGP to Enabled," is not necessary to enable connectivity between a route-based gateway and a policy-based VPN device. Option C, "Set Use Azure Private IP Address to Enabled," is not relevant to this scenario. This setting is used to specify whether the virtual network gateway should use a private or public IP address for the VPN connection.
upvoted 27 times
...
RageshBethapudi
Highly Voted 2 years, 8 months ago
correct answer is D. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps
upvoted 16 times
...
620b351
Most Recent 7 months, 4 weeks ago
Selected Answer: D
Correct answerd is D. BGP is not mandatory to have a S2S VPN.
upvoted 1 times
...
vDreams
1 year, 8 months ago
correct answer is D. BGP will trade routes, not the algorithm to setup the VPN. Also, as per documentation (https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-bgp-overview#why) is an optional feature to use as Route-Based. https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-bgp-overview#why
upvoted 1 times
...
khanda
2 years, 1 month ago
Selected Answer: D
Correct answer is D
upvoted 1 times
...
Chezzer83
2 years, 1 month ago
Selected Answer: D
I assumed D for this. BGP is not required to configure a VPN connection.
upvoted 2 times
...
where2go
2 years, 1 month ago
Its D --- The configuration option is part of the custom IPsec/IKE connection policy. If you enable the policy-based traffic selector option, you must specify the complete policy (IPsec/IKE encryption and integrity algorithms, key strengths, and SA lifetimes). The configuration option is part of the custom IPsec/IKE connection policy. If you enable the policy-based traffic selector option, you must specify the complete policy (IPsec/IKE encryption and integrity algorithms, key strengths, and SA lifetimes).
upvoted 1 times
...
bennasu
2 years, 2 months ago
If you set the IPsec/IKE config to default, under most of the circumstances, azure VPN GW will automatically match the on prem Firewall's IPsec Phase 1 and phase 2 configuration(modern FW like fortigate,sonicwall). But if you are using cisco ASA then it's a different story. You would need to configure the phase manually
upvoted 1 times
...
Bbb78
2 years, 3 months ago
I am not sure any of the 4 answers are correct. Mainly because this is ENABLED - "Use policy based traffic selector " ...if the onPrem device(s) is route based then this is not needed ?
upvoted 1 times
...
sserna
2 years, 3 months ago
En examen 20/01/2023
upvoted 2 times
...
mm2
2 years, 4 months ago
Selected Answer: D
route-based also mean static routes and all others routing protocols, when policy based, based on configured networks that should be routed for this specific VPN. From network perspective route-based use ROUTING TABLE to make route decision, this includes all directly connected networks and mentioned static routes. Making an assumption that BGP=Route-based as a must - is wrong imho however you can configure route-based to communicated with multiple policy base devices. Please notice POLICY BASE DEVICES for on prem, not DEVICE [one], there are multiple in question.
upvoted 2 times
...
mm2
2 years, 4 months ago
route-based also mean static routes and all others routing protocols, when policy based, based on configured networks that should be routed for this specific VPN. From network perspective route-based use ROUTING TABLE to make route decision, this includes all directly connected networks and mentioned static routes. Making an assumption that BGP=Route-based as a must - is wrong imho.
upvoted 1 times
...
zukako
2 years, 4 months ago
Not have to set BGP if onpremise is act/stanby
upvoted 1 times
...
Andre369
2 years, 5 months ago
Selected Answer: D
correct answer is D. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps
upvoted 1 times
...
JRodJ
2 years, 5 months ago
I don't think any of these answers is correct. In order to talk to on premises there is another button that must be enabled not visible on this screenshot. Use custom traffic selectors and it needs to be enabled. I have verified this works by configuring it at my customer's location with 3 separate sites.
upvoted 1 times
...
Libaax01
2 years, 6 months ago
The correct answer is D, you can not have Policy based VPN one end and Route Based VPN on the other. Both ends need to match on the type of VPN being used.
upvoted 1 times
...
Prutser2
2 years, 7 months ago
Selected Answer: D
Previously, when working with policy-based VPNs, you were limited to using the policy-based VPN gateway Basic SKU and could only connect to 1 on-premises VPN/firewall device. Now, using custom IPsec/IKE policy, you can use a route-based VPN gateway and connect to multiple policy-based VPN/firewall devices. To make a policy-based VPN connection using a route-based VPN gateway, configure the route-based VPN gateway to use prefix-based traffic selectors with the option "PolicyBasedTrafficSelectors". as per https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago