Last 2 options are correct. Link to the document in question has below details:
The
Azure virtual network hosts virtual machines. Network traffic originating from virtual machines on the Azure virtual network gets forwarded to the VPN
gateway (subnet), which then forwards the traffic across the site-to-site VPN connection to the VPN device on the on-premises network.
If the response helped, do "Mark as answer" and upvote it
- Vaibhav