certslothcertsloth
AZ-700/Topic 03

Azure / Associate

VPN, ExpressRoute and Virtual WAN

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: A hybrid path needs non-overlapping addresses, compatible routing and tested redundancy.

Must remember

  • Plan address space, subnet growth, gateway subnets and route limits. Use system routes, UDRs and BGP deliberately; longest-prefix matching precedes equal-prefix route-source preference. Network virtual appliances need IP forwarding and a valid return path.
  • Site-to-site VPN connects networks over IPsec; point-to-site connects individual clients. Select gateway SKU, route-based/policy compatibility, authentication and protocols according to the scenario. Active-active designs and BGP can improve availability, but client/on-premises equipment must support the topology.
  • ExpressRoute uses provider connectivity and peering to reach supported Microsoft services; private peering serves Azure private networking. It is not inherently end-to-end encrypted. ExpressRoute gateways, circuit bandwidth, provider paths and regional/global reach features have separate constraints.
  • Design redundant circuits/locations where the availability requirement demands it. A single provider path can remain a common failure point. VPN backup needs suitable routes, capacity and failover testing; equal physical capacity does not guarantee equal application throughput.
  • Virtual WAN supplies managed hub connectivity and routing capabilities. Hub route tables, associations, propagation and routing intent affect which traffic reaches firewalls or other networks. VNet peering gateway transit and use-remote-gateway settings solve a different topology and have compatibility constraints.
  • Hybrid DNS uses Private Resolver inbound/outbound endpoints and forwarding rulesets or another supported resolver design. Link the correct private zones, prevent loops and permit required UDP/TCP traffic. Network connectivity alone does not share DNS resolution.

Choose under exam pressure

Requirement Choice and reason
Remote users need individual VPN access Point-to-site VPN.
Managed hub connectivity across branches/VNets Virtual WAN when its routing/operating model fits.
Dedicated provider connectivity ExpressRoute, with separate encryption and resilience decisions.

Traps

  • A second logical connection may share the same physical failure domain.
  • BGP advertisements do not create all subnet/return routes automatically.
  • Peering and Virtual WAN do not erase overlapping-address constraints.

Active recall

1. What should be checked before joining networks?

Address overlap, routing policy, bandwidth, DNS and security requirements.

2. Does ExpressRoute itself guarantee application TLS?

No. Application encryption and circuit connectivity are separate.

3. Why test VPN backup under load?

It may have different throughput, latency and routing convergence than the primary circuit.

4. What makes a UDR through an NVA usable?

A healthy forwarding appliance and coherent forward/return paths.

5. Which DNS component accepts hybrid queries into Azure resolution?

An appropriately configured Private Resolver inbound endpoint.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.