AZ-305 Design infrastructure solutions Practice Question
A company has multiple Azure virtual networks (VNets) in different Azure regions and an on-premises data center connected via ExpressRoute. They want to connect all VNets to each other and to the on-premises network securely over the Microsoft global backbone. They also want to simplify management by using a single orchestration interface. Which Azure service should they use?
⚠ Common exam trap
It's easy for candidates to confuse VNet peering (which is point-to-point) with the hub-and-spoke model of Virtual WAN, or assume ExpressRoute alone can connect multiple VNets, missing the requirement for a single orchestration interface and transitive routing across regions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Virtual WAN
Azure Virtual WAN is correct because it provides a hub-and-spoke architecture that connects branch offices, VNets, and on-premises networks over the Microsoft global backbone. It offers a single orchestration interface for managing connectivity, routing, and security policies across multiple regions and ExpressRoute circuits, meeting the requirement for secure, global connectivity with simplified management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Virtual WAN
Why this is correct
Azure Virtual WAN deploys regional hubs that are connected by a Microsoft-backbone mesh, enabling any-to-any transit between spokes, branches, and on-premises sites without manually defining each pairing. Each hub aggregates VPN, ExpressRoute, and point-to-site gateways, and route propagation is automatically managed with virtual hub routing tables, so organizations can scale to multiple VNets and regions with a single orchestration plane. This is exactly the centralized multi-region interconnection and branch integration the scenario requires.
- ✗
VNet peering
Why it's wrong here
VNet peering establishes a direct, non-transitive layer-3 link between exactly two VNets in the same or different regions, but it does not forward traffic through any intermediate VNet by default. Peer connectivity is pairwise, so interconnecting a handful of regional VNets requires a full mesh of peering objects, and there is no built-in routing table orchestration, branch access, or centralized operations dashboard. In addition, peering alone cannot present a global WAN service—it simply moves packets between the two peered VNets you explicitly configure.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway is a per-VNet device that builds an IPsec/IKE site-to-site tunnel to on-premises or another Azure VNet, and it supports active-active and ExpressRoute coexistence, but it is not a multi-region backbone product. Connecting multiple regional VNets would require you to configure and manage gateway-to-gateway tunnels for each pair, which lacks automatic route exchange between all VNets and does not yield the hub-and-spoke orchestration offered by Virtual WAN. Its primary role is site-to-site and point-to-site access, not an integrated meshed WAN spanning many regional VNets.
- ✗
Azure ExpressRoute
Why it's wrong here
ExpressRoute provisions a dedicated, private Layer-3 circuit from an on-premises network to a Microsoft edge or partner network, giving high throughput and low latency for connectivity to Azure services. A separate virtual network gateway on each VNet is still required for traffic to flow over the circuit, and while one ExpressRoute circuit can reach multiple VNets through auth keys and service provider wiring, it does not route VNet-to-VNet traffic or maintain any topology among those VNets. It is therefore a connectivity circuit, not a regional VNet interconnection or orchestration mechanism.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.