AZ-305 Design infrastructure solutions Practice Question
A company deploys Azure VNets in multiple regions and has on-premises data centers. They need to connect all VNets to each other and to on-premises sites using the Microsoft global network for optimal routing. They also want to simplify management by using a single orchestration interface. Which Azure service should they use?
⚠ Common exam trap
Test-takers frequently confuse Azure Virtual WAN with a simple VPN gateway or peering solution, overlooking that Virtual WAN is specifically designed for large-scale, multi-region, multi-site connectivity with a single management plane, while the other options are point solutions that require complex manual configuration to achieve the same result.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Virtual WAN
Azure Virtual WAN (D) is correct because it provides a hub-and-spoke architecture that connects VNets across multiple regions and on-premises sites using the Microsoft global network for optimal routing. It offers a single orchestration interface (the Virtual WAN portal/API) to manage all connectivity, including site-to-site VPN, ExpressRoute, and VNet-to-VNet traffic, simplifying management and ensuring traffic traverses Microsoft's backbone rather than the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Virtual Network peering
Why it's wrong here
Azure Virtual Network peering creates a point-to-point connection between exactly two virtual networks, using Azure's private backbone only between those VNets. It cannot directly terminate on-premises connections, and it lacks a centralized management plane for routing policy across many regions and sites. To connect on-premises, you would still need to attach an additional gateway (VPN or ExpressRoute) to one of the peered VNets, and scaling to many VNets requires manually configuring each peering relationship. This makes it a suboptimal choice compared to a service that natively aggregates multi-region and on-premises connectivity.
- ✗
Azure VPN Gateway with multi-site connections
Why it's wrong here
Azure VPN Gateway with multi-site connections allows a single VPN gateway to terminate Site-to-Site IPsec tunnels from multiple on-premises locations, but it is still deployed per VNet and does not natively interconnect other VNets across regions without additional peering or routing configuration. Traffic to and from on-premises is typically encrypted over the public internet (or through a partner provider), not necessarily using the Microsoft backbone for all routing—though some paths may use it depending on configuration. It also lacks a global management plane; each VPN gateway must be configured individually, and multi-region VNet-to-VNet connectivity would require VNet peering or additional gateway settings. Thus, while it can handle multiple sites, it does not provide the consolidated, centrally managed global network fabric that a Virtual WAN does.
- ✗
Azure ExpressRoute Gateway
Why it's wrong here
Azure ExpressRoute Gateway is the Azure-side gateway object that connects an ExpressRoute circuit to a single virtual network, providing private, high-bandwidth connectivity between on-premises and that specific VNet. It does not, by itself, create links between multiple VNets—those VNets still need VNet peering or a hub-and-spoke topology with user-defined routes to communicate. It also does not provide a centralized management interface across regions; each ExpressRoute Gateway lives inside one VNet and applies to that VNet only. While ExpressRoute is a premium connectivity option, the gateway alone is not a replacement for a transit or global WAN architecture like Virtual WAN, which can incorporate ExpressRoute circuits as one of its connection types.
- ✓
Azure Virtual WAN
Why this is correct
Azure Virtual WAN is a Microsoft-managed, hub-and-spoke networking service that connects VNets and on-premises branches through a global mesh over the Microsoft backbone. Each regional virtual hub contains a scalable router that automatically computes routes between all attached VNets and remote sites, and hubs in different regions are automatically interconnected to provide any-to-any connectivity. It supports Site-to-Site VPN, Point-to-Site VPN, and ExpressRoute, all managed from a single pane of glass, which dramatically simplifies multi-region and multi-site administration. Because it centralizes routing, security policies (via Virtual WAN Secured Hubs and Azure Firewall Manager), and connectivity, it is the correct choice for a company with VNets in multiple regions plus on-premises locations.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.