Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company is migrating on-premises applications to Azure. They require that all traffic between Azure resources and on-premises resources traverse a private connection. They also want to reduce the attack surface by eliminating exposure of management endpoints over the internet. Which solution should they implement?

⚠ Common exam trap

Many candidates confuse Azure VPN Gateway with ExpressRoute, thinking that an encrypted tunnel provides equivalent privacy and security, but VPN Gateway still uses the public internet for transit, whereas ExpressRoute is a dedicated private connection that completely bypasses the internet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure ExpressRoute with Private Link for Azure services

Azure ExpressRoute provides a private, dedicated connection from on-premises to Azure, bypassing the public internet. By combining ExpressRoute with Private Link for Azure services, you ensure that traffic to Azure PaaS services (e.g., Azure SQL, Storage) traverses only the private connection and that the service endpoints are not exposed over the internet, reducing the attack surface. This directly meets the requirement for private connectivity and elimination of public management endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a stateful, cloud-native network security service that filters inbound and outbound traffic based on rules, threat intelligence, and NAT, but it never establishes a physical or virtual private connection between on-premises and Azure. It operates only on traffic that has already reached Azure and cannot replace the private transit path provided by ExpressRoute. In a hybrid architecture, a firewall is a security control to place after a connection exists, not the connection itself.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global Layer 7 (HTTP/HTTPS) application delivery controller that routes web traffic across the internet using anycast, global load balancing, and web application firewall capabilities. It is designed to optimize availability and performance for public web endpoints, not to provide a private, isolated network path from your on-premises infrastructure to Azure services. Because it relies on internet traffic for client connections, it cannot serve as a private hybrid connectivity solution.

  • ✓

    Azure ExpressRoute with Private Link for Azure services

    Why this is correct

    Azure ExpressRoute creates a dedicated private circuit from your on-premises network into Azure through an MPLS or other network provider, completely bypassing the public internet to reduce latency and improve security. Pairing it with Azure Private Link extends your virtual network's private IP space to Azure PaaS services via private endpoints, so traffic between your datacenter and those services never traverses a public endpoint. This combination offers both a private transit network and private access to individual services, meeting strict compliance and isolation requirements.

  • ✗

    Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway establishes encrypted IPsec/IKE tunnels over the public internet between your on-premises VPN device and the gateway in Azure; while data is encrypted, the underlying path is shared internet infrastructure with variable latency and potential congestion. VPN Gateway can provide secure site-to-site connectivity but is not a dedicated private connection and generally offers lower bandwidth limits than ExpressRoute. Moreover, without Private Link, traffic to Azure PaaS services can still be directed to public endpoints, so a VPN alone does not deliver the same private service access as ExpressRoute combined with Private Link.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.