Design infrastructure solutions1 / 5
A company needs to implement Azure Virtual Network encryption to ensure all traffic between VMs in the same VNet is encrypted in transit. The VMs run Linux and Windows workloads. Which solution should you recommend?
CorrectIncorrect
Alex
Azure Virtual Network encryption uses DTLS (Datagram Transport Layer Security) to encrypt traffic between VMs within the same VNet and across peered VNets. It requires Accelerated Networking enabled on VM NICs and supported VM SKUs. The feature encrypts private IP to private IP traffic at the host level, enhancing existing encryption-in-transit capabilities. Limitations include: no support for Azure DNS Private Resolver, Application Gateway, Azure Firewall, or ExpressRoute Gateways in encrypted VNets. Currently only AllowUnencrypted enforcement is GA. Exam tip: VNet encryption = DTLS between VMs. Requires Accelerated Networking. Does NOT support App Gateway, Azure Firewall, or ExpressRoute Gateway in same VNet.
Sourcelearn.microsoft.com
Follow-up answers are available in the app. Create a free account — no credit card required.
Question 1 of 5
Create a free account