Courseiva

AZ-305 Design infrastructure solutions Practice Question

A multinational corporation needs to design a global DNS solution for Azure resources. They require automatic failover across Azure regions and low-latency responses based on the client's geographic location. The solution must also support custom domains without exposing the underlying Azure public IP addresses. Which combination of Azure services should they use?

⚠ Common exam trap

Many exam-takers confuse regional services like Application Gateway with global services like Front Door, and assuming that DNS-based routing alone (Traffic Manager) can achieve low-latency geographic routing without the anycast edge network of Front Door.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Traffic Manager with geographic routing and Azure Front Door

Azure Front Door provides global load balancing with automatic failover across regions and low-latency routing based on the client's geographic location via its anycast protocol. Azure Traffic Manager with geographic routing complements this by directing traffic to specific regional endpoints based on the client's origin, and together they support custom domains while hiding the underlying Azure public IP addresses through Front Door's frontend endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Traffic Manager with geographic routing and Azure Front Door

    Why this is correct

    Azure Traffic Manager with geographic routing is the correct DNS-level mechanism for a multinational workload because it uses the client’s source DNS resolver location to select the optimal regional endpoint, enabling true global load balancing. Azure Front Door complements it by terminating HTTPS at the edge, providing the custom domain and managed TLS certificates, and allowing the origin to be exposed privately via private link, which is essential when user-facing traffic can’t hit the endpoint directly. Together they deliver global DNS failover plus application-layer routing and security, which is why this is the required combination.

  • ✗

    Azure Application Gateway with Azure Front Door

    Why it's wrong here

    Azure Application Gateway is a regional, layer-7 load balancer that operates within a single Azure region and cannot participate in global DNS-based traffic routing, so it adds no value for a multinational DNS design. Placing Azure Front Door in front of it does not make Application Gateway global; Front Door would handle the global edge, but the Application Gateway tier is still confined to a specific region and is not the component that answers the question’s need for global DNS routing. The scenario calls for Traffic Manager’s geographic routing, not a regional gateway that simply forwards to backends within one deployment.

  • ✗

    Azure DNS with Azure Traffic Manager

    Why it's wrong here

    Azure DNS is only an authoritative DNS hosting service: it publishes records and performs name resolution, but it does not steer traffic based on endpoint health, geography, or latency. While pairing it with Azure Traffic Manager would add DNS-level routing, the combination still fails to provide the HTTPS edge features—such as custom domain support and private endpoint connectivity—that Azure Front Door supplies for a globally distributed application. Without Front Door, the architecture has no global anycast entry point or application-layer protection, so it is incomplete for this requirement.

  • ✗

    Azure Traffic Manager with priority routing and Azure Application Gateway

    Why it's wrong here

    Traffic Manager’s priority routing sends all traffic to the first available endpoint and only fails over to the second, which is not appropriate for a multinational deployment that expects requests to land at the nearest regional endpoint based on user geography—priority routing ignores location and latency. Azure Application Gateway is also a regional service that does not hide the origin IP on a global scale because it only represents one regional front end, so putting it behind Traffic Manager doesn’t add the global custom-domain and private-endpoint capabilities that Front Door provides. Geographic routing, not priority, and Front Door, not Application Gateway, are the correct choices.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.