A bank moves tens of terabytes a day between its own datacentre and Azure. It needs predictable throughput, and its regulator objects to that traffic crossing the public internet at all. Which connectivity option should it buy?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct ExpressRoute

Correct. ExpressRoute is a private connection arranged through a connectivity provider: the traffic does not traverse the public internet, and the circuit is bought at a committed bandwidth rather than depending on whatever the internet is doing today.

Not correct A site-to-site VPN over the internet

Wrong for this requirement. The tunnel is encrypted, but it runs across the public internet, so throughput and latency depend on a path nobody controls — and 'not on the public internet' was stated explicitly.

Not correct A point-to-site VPN from each server in the datacentre

Wrong. Point-to-site connects one device at a time and is designed for individual remote users, not for a datacentre's continuous bulk traffic.

Not correct Virtual network peering to the bank's datacentre network

Wrong. Peering connects two Azure virtual networks. A datacentre is not one, so there is nothing to peer with.

Why

A VPN gateway is a tunnel across the internet; ExpressRoute is a wire that avoids it. The VPN is quick to set up, cheap, and shares the internet's variability; ExpressRoute takes a provider and a lead time and gives higher bandwidth, more consistent latency and no public transit. Site-to-site connects networks, point-to-site connects individual devices, and both are gateway features rather than separate services.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.compute-and-networking

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services