← All AZ-700 Flashcard Decks

VPN Gateway Flashcards

6 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 VPN Gateway flashcards as text
  1. Which protocol must be used for Point-to-Site VPN when Azure AD authentication is selected?

    Answer: OpenVPN

    Azure AD authentication for P2S VPN is only supported with the OpenVPN protocol.

  2. What is the function of BGP in Azure VPN Gateway?

    Answer: Dynamically exchanges routes between Azure and on-premises networks

    BGP enables dynamic route exchange between Azure VPN Gateway and on-premises BGP-capable devices, removing the need for static route management.

  3. In an active-active VPN Gateway configuration, what is created to ensure high availability?

    Answer: Two gateway instances each with their own public IP and BGP peer

    Active-active mode deploys two gateway instances, each with its own public IP, establishing dual tunnels for redundancy.

  4. Which IKE version does Azure VPN Gateway use by default for Route-based VPN connections?

    Answer: IKEv2

    Azure VPN Gateway defaults to IKEv2 for route-based VPN connections, though IKEv1 is supported for policy-based connections.

  5. What Azure resource must be provisioned in the GatewaySubnet before deploying a VPN Gateway?

    Answer: A public IP address resource

    A Public IP address resource must be created and associated with the VPN Gateway before deployment.

  6. What is the recommended GatewaySubnet CIDR size for a production VPN Gateway deployment to support future scaling?

    Answer: /27 or larger

    Microsoft recommends using /27 or larger for GatewaySubnet to accommodate additional gateway resources and future ExpressRoute coexistence.