Drag or tap steps into the slots.
AZ-305 Design data storage solutions Practice Question
Drag and drop the steps to deploy a web app using Azure App Service with a custom domain and SSL certificate into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Create the App Service app, then map the custom domain, then upload the SSL certificate, then bind the certificate to the domain, then enforce HTTPS.
The correct order for deploying a web app using Azure App Service with a custom domain and SSL certificate is: create the App Service app, map the custom domain, upload the SSL certificate, bind the certificate to the domain, and finally enforce HTTPS. This sequence ensures that each step has the necessary prerequisites: the app exists before domain mapping, the domain is mapped before certificate upload and binding, and the certificate is bound before enforcing HTTPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create the App Service app, then map the custom domain, then upload the SSL certificate, then bind the certificate to the domain, then enforce HTTPS.
Why this is correct
This is the correct order because you must first have the app, then map the domain so that the app knows which domain to expect, then upload the certificate, then bind it to the domain, and finally enforce HTTPS to ensure all traffic uses SSL.
- ✗
Create the App Service app, then upload the SSL certificate, then map the custom domain, then bind the certificate to the domain, then enforce HTTPS.
Why it's wrong here
This is incorrect because you should map the custom domain before uploading the certificate. Without the domain mapped, you cannot properly bind the certificate to the correct domain, and the upload step depends on knowing the domain context.
- ✗
Create the App Service app, then map the custom domain, then bind the certificate to the domain, then upload the SSL certificate, then enforce HTTPS.
Why it's wrong here
This order fails because binding a certificate to a custom domain requires the certificate to already exist within the App Service resource. The SSL binding pane in the portal displays only certificates that have been uploaded to the App Service, so attempting to bind before upload leaves no certificate thumbprint to select. Uploading the certificate after the binding step creates a certificate that is never attached to the domain, meaning the site would still serve HTTP and the binding would not exist.
- ✗
Map the custom domain, then create the App Service app, then upload the SSL certificate, then bind the certificate to the domain, then enforce HTTPS.
Why it's wrong here
Custom domain mapping cannot be performed against a non-existent App Service app because the mapping operation stores the hostname in the site's app settings and validates ownership using DNS records tied to the app's default hostname (e.g., contoso.azurewebsites.net). Without the app resource in place, there is no target resource ID for Azure to assign the domain to, and no verification record can be generated. Creating the app afterward cannot retroactively import the preexisting domain mapping because no such mapping was ever persisted.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.