20+ practice questions focused on Design infrastructure solutions — one of the most tested topics on the Microsoft Azure Solutions Architect Expert AZ-305 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Design infrastructure solutions PracticeA company has multiple Azure subscriptions and on-premises data centers connected via ExpressRoute. They want to centralize connectivity to the internet and enforce a single web filtering and security policy for all outbound internet traffic from Azure VMs. Which Azure networking architecture should they implement?
Explanation: A hub-spoke topology with Azure Firewall in the hub provides a centralized point for routing all outbound internet traffic from Azure VMs. By using user-defined routes (UDRs) on the spoke subnets that point to the Azure Firewall as the default gateway (0.0.0.0/0 next hop), all outbound traffic is forced through the firewall, enabling consistent web filtering and security policy enforcement. This architecture also integrates seamlessly with ExpressRoute for on-premises connectivity, ensuring a single egress point for internet-bound traffic.
A company is developing a containerized microservices application. They want to minimize operational overhead for managing orchestration. The application has a low-to-medium traffic pattern that can spike unpredictably. They need fast scaling and pay-per-second billing. Which Azure compute service should they use?
Explanation: Azure Container Apps provides a serverless platform for microservices with built-in service discovery, autoscaling, and pay-per-second billing, while abstracting away the Kubernetes control plane. ACI, while serverless and per-second billed, does not offer native orchestration features such as service discovery or revision management, making it less suitable for a containerized microservices application.
A company has an Azure API Management instance deployed in the internal virtual network (VNet) mode. They want to securely expose their backend APIs to external partners over the internet. External partners need to authenticate using OAuth2 tokens. The company also wants to enforce rate limits (throttling) per subscription, cache responses, and enable CORS. Which Azure service should they use to expose the APIs?
Explanation: Azure API Management in internal mode places the gateway on a private IP inside a VNet and does not accept public internet traffic. To securely expose the backend APIs to external partners, you must put a public entry point, such as Azure Application Gateway, in front of the internal APIM. Application Gateway provides public access, and APIM continues to handle OAuth2 validation, rate limiting, caching, and CORS policies.
A company has deployed Azure virtual machines without public IP addresses. They need to provide secure RDP and SSH access to these VMs for administrators from the corporate network (on-premises). The solution must integrate with Microsoft Entra ID for authentication and support multi-factor authentication (MFA). It must not require any public endpoint exposure on the VMs. Which Azure service should they use?
Explanation: Azure Bastion provides secure RDP and SSH connectivity to Azure VMs directly from the Azure portal over TLS, without exposing any public IP addresses on the VMs. It integrates with Microsoft Entra ID for authentication and can enforce MFA through conditional access policies, meeting all stated requirements.
A company has multiple Azure virtual networks (VNets) in different regions and an on-premises data center. They need to implement a hub-and-spoke topology where the hub VNet hosts shared services like firewalls and DNS. All traffic between spokes, and between spokes and on-premises, must be routed through the hub for inspection. Additionally, spoke VNets must not be able to directly communicate with each other. Which Azure networking solution should they implement to meet these requirements with minimal administrative overhead?
Explanation: Azure Virtual WAN with routing policies is the correct choice because it provides a managed hub-and-spoke topology that routes all traffic between spokes and on-premises through the hub for inspection. By configuring routing policies, you can enforce spoke isolation and direct traffic to network virtual appliances (NVAs) for inspection, minimizing administrative overhead through centralized routing policies without the need for manual UDRs or complex peering configurations.
+15 more Design infrastructure solutions questions available
Practice all Design infrastructure solutions questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Design infrastructure solutions. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Design infrastructure solutions questions on the AZ-305 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Design infrastructure solutions is tested as part of the Microsoft Azure Solutions Architect Expert AZ-305 blueprint. Practicing with targeted Design infrastructure solutions questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free AZ-305 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Design infrastructure solutions is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Design infrastructure solutions practice session with instant scoring and detailed explanations.
Start Design infrastructure solutions Practice →