AZ-305 Design infrastructure solutions Practice Question
A company has Azure virtual networks (VNets) in three different Azure regions and an on-premises data center connected via ExpressRoute. They need to connect all VNets to each other and to on-premises over the Microsoft global backbone. They also require centralized management of routing and the ability to enforce security policies such as forced tunneling for internet-bound traffic. Which Azure service should they use?
⚠ Common exam trap
Many candidates confuse Azure Virtual Network Manager (a connectivity configuration tool) with Azure Virtual WAN (a full SD-WAN solution), overlooking that Virtual WAN provides the actual routing, global transit, and integrated security enforcement required for multi-region and hybrid connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Virtual WAN
Azure Virtual WAN is the correct choice because it provides a hub-and-spoke architecture that connects VNets across regions and on-premises via the Microsoft global backbone, with built-in centralized routing management and the ability to enforce security policies like forced tunneling through integrated Azure Firewall or third-party NVAs. It meets all requirements: multi-region VNet connectivity, ExpressRoute integration, and centralized policy control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Virtual Network Manager
Why it's wrong here
Azure Virtual Network Manager provides centralized governance of VNets through network groups, allowing you to apply connectivity configurations (such as mesh or hub-and-spoke) and security admin rules. However, it is fundamentally a management-plane service: it does not deploy any gateway infrastructure, perform data-plane packet forwarding, or offer global transit routing between VNets or from VNets to on-premises. Its connectivity configurations are for defining logical topology, not for actually routing traffic across regions.
- ✓
Azure Virtual WAN
Why this is correct
Azure Virtual WAN is Microsoft's global transit networking service that builds a hub-and-spoke architecture with virtual hubs deployed in each region. Each virtual hub contains integrated VPN, ExpressRoute, and (optionally) Azure Firewall components, and the hubs are interconnected via Microsoft's high-speed backbone, enabling VNet-to-VNet, branch-to-VNet, and remote-user-to-VNet connectivity. It automatically manages routing tables, supports forced tunneling, and provides centralized policy management, making it the correct choice when you need reliable global transit between VNets in three different regions and on-premises connectivity.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, stateful network security service that filters L3-L7 traffic based on application and network rules, and it can be deployed in a hub VNet or as part of a Virtual WAN secure hub. However, Azure Firewall does not create any network connectivity by itself; it only inspects and controls traffic that is routed through it. Without a separate transit routing mechanism such as a Virtual WAN hub or a network virtual appliance, placing a firewall cannot interconnect VNets in different Azure regions or provide the global transit path needed for on-premises connectivity.
- ✗
Azure Route Server
Why it's wrong here
Azure Route Server is a managed service that enables dynamic BGP peering between network virtual appliances (NVAs) and Azure's software-defined network, allowing NVAs to exchange routes with the VNet and learn Azure routes. It acts solely as a route-exchange point for third-party NVAs; it does not forward packets, provide global transit, or automatically interconnect VNets across different regions. Since it lacks integrated VPN/ExpressRoute gateways and does not supply any data-plane forwarding, it cannot serve as a replacement for Azure Virtual WAN when the requirement is multi-region, on-premises-connected transit networking.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 212 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.