An auditor asks whether the traffic flowing over your ExpressRoute circuit is encrypted. What is the accurate answer?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct It is private but not encrypted by default; where the data must be encrypted in transit you add encryption yourself, for example a tunnel over the circuit or TLS in the application

Correct. ExpressRoute's guarantee is that the traffic does not cross the public internet. Confidentiality on the wire is a separate control you choose to add.

Not correct Yes — all ExpressRoute traffic is encrypted by the platform in the same way as a VPN tunnel

Wrong, and it borrows the VPN's property. A site-to-site VPN encrypts because it must: it crosses the public internet. ExpressRoute solves that problem by avoiding the internet, not by encrypting.

Not correct Yes — because it avoids the public internet, encryption is unnecessary and Azure applies it anyway

Wrong on both halves. Avoiding the internet is not the same as making encryption unnecessary (many regimes require encryption in transit regardless of the path), and it is not applied automatically.

Not correct No, and there is no way to encrypt traffic over an ExpressRoute circuit

Wrong. You can run an encrypted tunnel across the circuit, and applications can use TLS as they would anywhere else. The point is that it is your decision rather than an automatic property.

Why

Private and encrypted are two different words and auditors are usually asking about the second one. ExpressRoute buys a path that does not traverse the public internet, with the bandwidth and latency characteristics of a circuit you have bought; a VPN gateway buys an encrypted tunnel across a path you do not control. Needing both is normal, and it is a design you assemble rather than a checkbox.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.compute-and-networking

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services