AZ-305 Design infrastructure solutions Practice Question
A company is migrating on-premises applications to Azure. They require that all traffic between Azure resources and on-premises resources traverse a private connection. They also want to reduce the attack surface by eliminating exposure of management endpoints over the internet. Which solution should they implement?
⚠ Common exam trap
Many candidates confuse Azure VPN Gateway with ExpressRoute, thinking that an encrypted tunnel provides equivalent privacy and security, but VPN Gateway still uses the public internet for transit, whereas ExpressRoute is a dedicated private connection that completely bypasses the internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure ExpressRoute with Private Link for Azure services
Azure ExpressRoute provides a private, dedicated connection from on-premises to Azure, bypassing the public internet. By combining ExpressRoute with Private Link for Azure services, you ensure that traffic to Azure PaaS services (e.g., Azure SQL, Storage) traverses only the private connection and that the service endpoints are not exposed over the internet, reducing the attack surface. This directly meets the requirement for private connectivity and elimination of public management endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a stateful, cloud-native network security service that filters inbound and outbound traffic based on rules, threat intelligence, and NAT, but it never establishes a physical or virtual private connection between on-premises and Azure. It operates only on traffic that has already reached Azure and cannot replace the private transit path provided by ExpressRoute. In a hybrid architecture, a firewall is a security control to place after a connection exists, not the connection itself.
- ✗
Azure Front Door
Why it's wrong here
Azure Front Door is a global Layer 7 (HTTP/HTTPS) application delivery controller that routes web traffic across the internet using anycast, global load balancing, and web application firewall capabilities. It is designed to optimize availability and performance for public web endpoints, not to provide a private, isolated network path from your on-premises infrastructure to Azure services. Because it relies on internet traffic for client connections, it cannot serve as a private hybrid connectivity solution.
- ✓
Azure ExpressRoute with Private Link for Azure services
Why this is correct
Azure ExpressRoute creates a dedicated private circuit from your on-premises network into Azure through an MPLS or other network provider, completely bypassing the public internet to reduce latency and improve security. Pairing it with Azure Private Link extends your virtual network's private IP space to Azure PaaS services via private endpoints, so traffic between your datacenter and those services never traverses a public endpoint. This combination offers both a private transit network and private access to individual services, meeting strict compliance and isolation requirements.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway establishes encrypted IPsec/IKE tunnels over the public internet between your on-premises VPN device and the gateway in Azure; while data is encrypted, the underlying path is shared internet infrastructure with variable latency and potential congestion. VPN Gateway can provide secure site-to-site connectivity but is not a dedicated private connection and generally offers lower bandwidth limits than ExpressRoute. Moreover, without Private Link, traffic to Azure PaaS services can still be directed to public endpoints, so a VPN alone does not deliver the same private service access as ExpressRoute combined with Private Link.
Go deeper
Related to this question
Learn chapter
Event-Driven Architecture with Event Grid and Service Bus
Key term
ExpressRoute Design
ExpressRoute Design is the process of planning a dedicated, private network connection from an on-premises data center to Microsoft Azure, bypassing the public internet for improved reliability and speed.
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.