Two virtual networks in the same region, owned by two different subscriptions, must exchange traffic privately at low latency. The team does not want to deploy or pay for gateways and does not want the traffic on the public internet. What do you configure?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services easy

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Virtual network peering between them

Correct. Peering connects two virtual networks directly across the Microsoft backbone; resources address each other by private IP as though they shared one network, and no gateway is deployed.

Not correct A site-to-site VPN gateway on each side

Wrong here, although it would work. You would deploy and pay for a gateway at each end and accept the tunnel's throughput ceiling — sensible when one side is not in Azure, wasteful when both are.

Not correct Public IP addresses on each side, with network security group rules permitting the other

Wrong. That puts the traffic on the public internet, which the requirement explicitly rules out, and makes connectivity depend on address-based rules that break the day an address changes.

Not correct Move both virtual networks into the same resource group

Wrong. A resource group is a management container. Two virtual networks do not become connected by being filed in the same folder.

Why

The shortest way to hold this: Azure-to-Azure is peering, Azure-to-elsewhere is a gateway. Peering works between subscriptions and across regions (global peering), stays on the Microsoft backbone, and needs no gateway. Its one hard prerequisite is addressing — two networks whose address spaces overlap cannot be peered, which is the argument for planning ranges before anybody deploys anything.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.compute-and-networking

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services