AZ-305 Design infrastructure solutions Practice Question
An on-premises datacenter must connect privately to Azure with predictable bandwidth and avoid traversal of the public internet. Which connectivity option should be recommended?
⚠ Common exam trap
Many exam-takers confuse Site-to-site VPN (which also provides a private IP tunnel) as meeting the 'private' requirement, but it still traverses the public internet and cannot guarantee predictable bandwidth like ExpressRoute.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ExpressRoute
ExpressRoute provides a dedicated private connection from on-premises to Azure, bypassing the public internet entirely. It offers predictable bandwidth, low latency, and high reliability through a Layer 3 MPLS or direct fiber link from a connectivity provider. This meets the requirement for a private, consistent network path without internet traversal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion is a fully managed PaaS service that provides secure RDP/SSH access to virtual machines via the Azure portal over TLS. It brokers inbound management sessions from a browser into a virtual network, but it does not establish any forwarding path or tunnel between an on-premises datacenter and Azure. Therefore, Bastion is a control-plane access feature, not a hybrid connectivity option, and cannot satisfy the requirement for private datacenter connectivity.
- ✗
Point-to-site VPN
Why it's wrong here
Point-to-site VPN uses IKEv2, OpenVPN, or SSTP tunnels to connect individual remote client devices to an Azure virtual network through a VPN gateway. It is designed for teleworker or small-client scenarios, not for carrying aggregate traffic from an entire on-premises datacenter, and it lacks the capacity, redundancy, and routing architecture of a site-to-site or dedicated link. Even when encrypted, the connection originates from a single client and traverses public internet paths, so it does not create a private datacenter-to-cloud network.
- ✗
Site-to-site VPN only
Why it's wrong here
Site-to-site VPN connects the on-premises network to an Azure VPN gateway over an IPsec tunnel from a VPN device, enabling full network-to-network routing. However, that tunnel is carried across the public internet, so while the payload is encrypted, the underlying path is a shared, best-effort IP network with no dedicated bandwidth, latency guarantee, or ExpressRoute-grade SLA. For a datacenter requiring private connectivity to Azure, a VPN-only design is not a private connection; it is an internet-dependent overlay and therefore falls short of the requirement.
- ✓
ExpressRoute
Why this is correct
ExpressRoute provides a private, dedicated Layer 3 connection between your on-premises datacenter and Azure through a connectivity provider, using redundant Microsoft Enterprise Edge routers and BGP peering. Traffic never traverses the public internet, enabling consistent latency, higher bandwidth, and an availability SLA. With private peering, virtual networks can be reached directly over this backbone, making it the correct service for private datacenter-to-Azure connectivity.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.