Which TWO of these statements about virtual network peering are true?
Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Choose 2.
Correct Peering can connect virtual networks that sit in different Azure regions
True. That is global peering; the traffic still crosses the Microsoft backbone rather than the public internet, though of course you pay the distance in latency.
Correct Peering is not transitive: if A is peered with B and B with C, A cannot reach C simply because B sits in the middle
True, and it is the single most common surprise in hub-and-spoke designs. Traffic between spokes needs something in the hub — a gateway or a network virtual appliance — plus routing that sends it there.
Not correct Two virtual networks with overlapping address spaces can be peered as long as their subnets differ
False. Overlapping address space is exactly what peering cannot tolerate: with two claimants for the same address, routing has no correct answer, so the peering is refused.
Not correct Peered traffic travels over the public internet unless you add ExpressRoute
False. Peered traffic stays on the Microsoft network. ExpressRoute is about reaching Azure privately from outside it, which is a different problem.
Not correct Peering merges the two networks' network security group rules automatically
False. Each subnet keeps its own rules. Peering provides the path; whether traffic is allowed along it is still decided explicitly at each end.
Why
Peering gives you a path and nothing else: private addressing, the Microsoft backbone, no gateway, across subscriptions and across regions. It withholds two things people expect — transitivity and any change to your security rules. Remember the hub-and-spoke consequence: spokes peered to a hub still cannot talk to each other until something in the hub routes between them.
Where this comes from
- Cited
- Microsoft AZ-900 study guide skill area architecture-and-services.compute-and-networking
Practise this
Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.
Practise Microsoft Certified: Azure Fundamentals (AZ-900)
More questions on this objective
- An image-resizing routine runs for about two seconds whenever a file lands in a storage container — perhaps two hundred times on a busy day, and not at all on a quiet one. The team wants to pay for the work done and maintain no servers. Which compute option fits? machine-checked
- A fifteen-year-old accounting application needs a kernel-level driver, a scheduled task that edits the registry, and a runtime version nobody supports any more. The business wants it running in Azure this quarter with as few code changes as possible. Where does it go? machine-checked
- A team runs nine small services, each with its own conflicting library versions. They want each one packaged with its dependencies, starting in seconds, several to a host, without a separate operating system per service. Which compute type are they describing? machine-checked
- Which TWO of these statements about Azure compute types are true? machine-checked
- A public website runs on four identical virtual machines behind a load balancer. Traffic triples while a television advert airs and falls back an hour later. The team wants instances added and removed automatically against CPU, all built from one image, with nobody clicking. Which option is designed for that? machine-checked
- Three virtual machines form a quorum-based cluster in a region that has no availability zones. You want them placed so that neither a single rack losing power nor a single batch of planned host maintenance can take all three at once. What do you configure? machine-checked