Courseiva
Design infrastructure solutionseasyMultiple ChoiceObjective-mapped

AZ-305 Design infrastructure solutions Practice Question

A company has an on-premises data center and wants to connect it to Azure with a dedicated, private network connection that is not routed over the public internet. They also need a higher service-level agreement (SLA) compared to VPN-based connections. Which Azure service should they use?

⚠ Common exam trap

It's easy for candidates to confuse Azure Virtual WAN as a direct replacement for ExpressRoute, but Virtual WAN is a management overlay that still requires ExpressRoute or VPN as the underlying transport, not a dedicated private connection itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure ExpressRoute

Azure ExpressRoute provides a dedicated, private connection from on-premises to Azure that bypasses the public internet, ensuring lower latency, higher reliability, and a 99.95% SLA (for dedicated circuits) compared to VPN-based connections. This meets the requirement for a private network connection with a higher SLA than VPN Gateway, which relies on internet-based IPSec tunnels with a 99.9% SLA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway uses IPsec/IKEv2 site-to-site tunnels that route encrypted traffic over the public internet, so availability and latency depend on your ISP and internet congestion. It does not deliver a dedicated, private circuit; instead, the VPN gateway endpoints still rely on public-facing IP addresses and internet routing. With a 99.95% SLA only for active-active deployments, it is a lower-grade connectivity option than ExpressRoute and is the wrong answer when the requirement is a private on-premises link.

  • Azure ExpressRoute

    Why this is correct

    Azure ExpressRoute establishes a logical private connection to Azure through a connectivity provider or direct peering, with traffic that never traverses the public internet. It uses BGP sessions over dedicated or co-located circuits, offering enterprise-grade reliability, high bandwidth (up to 100 Gbps), and native geographic redundancy across peering locations. The 99.95% SLA for dedicated circuits plus predictable latency make it the correct choice for a dedicated, private hybrid connection.

  • Azure Bastion

    Why it's wrong here

    Azure Bastion is a fully managed PaaS service that brokers Transport Layer Security (TLS)-secured RDP/SSH connections to individual Azure VMs via the Azure portal. It only addresses network-level perimeter management access, not private interconnectivity between your data center and Azure; there is no site-to-site or point-to-site VPN/ExpressRoute capability. Therefore, it can never satisfy a requirement to connect on-premises infrastructure to Azure, as it neither carries nor exposes customer router interfaces or routing tables.

  • Azure Virtual WAN

    Why it's wrong here

    Azure Virtual WAN is a hub-and-spoke orchestration framework that streamlines routing, security, and intra-site connectivity across VNets and branch networks, but it is not a physical transport path. To connect an on-premises data center, Virtual WAN must delegate to one of its supported attachments, such as an ExpressRoute circuit, Site-to-Site VPN, or VNet peering; without one of these, it provides no dedicated connection. Its role is therefore to manage and aggregate connectivity, not to replace the private circuit demanded in this scenario.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.