A canal reviewer treats ExpressRoute private peering as encrypted because the path is private. What should the security engineer state first?
Select an answer to reveal the explanation.
Short Explanation
Private path ≠ secret handshake. ExpressRoute isn’t encrypted by default—privacy of the pipe isn’t confidentiality. Add MACsec, IPsec overlay, or app TLS when the auditor wants crypto.
Full Explanation
ExpressRoute provides a private connectivity path but does not encrypt customer traffic by default. Confidentiality requires an added technology such as MACsec on ExpressRoute Direct, an IPsec VPN overlay over private peering, or application-layer TLS. Private peering alone does not enable MACsec on provider-managed circuits. FastPath and NSG service tags do not encrypt ExpressRoute frames.