Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company has multiple virtual networks in different Azure regions. They need to connect all VNets together securely over the Microsoft backbone. They also need to connect to an on-premises data center via ExpressRoute. The solution should support transitive routing between all connected networks. Which Azure service should they use?

⚠ Common exam trap

Many candidates choose Azure Virtual Network Peering (Option A) because they assume peering supports transitive routing, but Azure explicitly does not allow transitive routing through peered VNets unless you use a hub VNet with a network virtual appliance or enable gateway transit, which is not the same as native transitive routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Virtual WAN

Azure Virtual WAN is the correct choice because it provides a hub-and-spoke architecture that supports transitive routing between all connected networks (multiple VNets across regions and on-premises via ExpressRoute) over the Microsoft backbone. It natively integrates ExpressRoute and VPN gateways into a single managed service, enabling seamless connectivity and routing between any spoke VNet, branch, or on-premises site without requiring manual peering or gateway transit configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Virtual Network Peering

    Why it's wrong here

    Azure VNet peering is a direct, non-transitive connection between two virtual networks. To connect multiple VNets across different regions, you would need to create a full mesh of peerings, which grows exponentially and becomes hard to manage. Additionally, peering alone does not provide transitive routing to a central hub or on-premises network, so it fails to offer the consolidated connectivity that a hub-and-spoke architecture like Virtual WAN delivers.

  • ✗

    Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway can indeed connect VNets using IPsec tunnels, but this approach is cumbersome when many VNets are involved. Each VNet typically requires its own gateway, and inter-VNet transit via VPN gateways does not happen automatically; you must configure BGP routing explicitly and manage multiple S2S connections. This makes it operationally complex and less scalable than a managed service like Virtual WAN, which provides built-in transitive routing across all attached VNets.

  • ✓

    Azure Virtual WAN

    Why this is correct

    Azure Virtual WAN is the correct choice because it acts as a managed hub-and-spoke platform with automatic transitive routing between any connected VNets, regardless of region. Spoke VNets in different Azure regions can attach to the same Virtual WAN hub or to regional hubs, and traffic is routed over the Microsoft backbone with no need for manual peering or BGP. It also natively interconnects with VPN, ExpressRoute, and point-to-site gateways, making it the ideal centralized connectivity solution for multiple VNets.

  • ✗

    Azure ExpressRoute Gateway

    Why it's wrong here

    Azure ExpressRoute Gateway is designed to connect a single VNet to an ExpressRoute circuit for private, dedicated connectivity to on-premises or Microsoft services. It does not interconnect multiple VNets; each VNet must have its own ExpressRoute gateway, and traffic between those VNets cannot be transitively routed through the gateway or the ExpressRoute backbone. Therefore, using ExpressRoute Gateway alone would not satisfy the requirement of connecting multiple VNets across different regions.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.