AZ-305 Design infrastructure solutions Practice Question
You are designing a network architecture for a multi-tier application. The front-end tier is an Azure Application Gateway that routes traffic to a web app on Azure App Service. The back-end tier is an Azure SQL Database. You need to ensure that all traffic between the Application Gateway and the web app remains within the Azure backbone network, and that the web app can only be accessed through the Application Gateway. What should you configure?
⚠ Common exam trap
Candidates often confuse Service Endpoints with Private Link, assuming Private Link is required for private connectivity, but for App Service, Service Endpoints with IP restrictions are the correct and simpler solution for this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Service Endpoints for the web app and configure the Application Gateway with a private IP.
Enabling Service Endpoints for the web app allows traffic from the Application Gateway to reach the App Service over the Azure backbone network, bypassing the public internet. Configuring the Application Gateway with a private IP and restricting the web app's access to only that private IP ensures the web app can only be accessed through the gateway, meeting both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Private Link for the web app and disable public access.
Why it's wrong here
Private Link ensures traffic between Application Gateway and App Service remains within the Microsoft backbone, but it fails to restrict access solely through the Gateway because any resource within the same virtual network or a peered one can also reach the private endpoint directly, violating the requirement that the web app be accessible only via the Gateway. This option is tempting because Private Link is the standard method for privatising Azure PaaS services and eliminating public internet exposure, and would be correct if the goal were simply private connectivity without granular source restriction.
- ✓
Enable Service Endpoints for the web app and configure the Application Gateway with a private IP.
Why this is correct
Service Endpoints for the web app restrict inbound traffic to the front-end subnet of the Application Gateway, so only the gateway's subnet can reach the App Service over the Azure backbone, avoiding a hop through the internet. Configuring the Application Gateway with a private IP ensures the gateway itself is not publicly reachable and acts as the sole, internal ingress point. Together they satisfy the 'only via the gateway' requirement without moving the web app off its public endpoint or requiring an Azure Private Link connection.
- ✗
Deploy Azure Firewall in front of the Application Gateway.
Why it's wrong here
Deploying Azure Firewall in front of the Application Gateway adds a stateful, centralized NVA that inspects and filters traffic, but it does nothing to secure the network path between the Application Gateway and the App Service. It also introduces significant operational overhead and hourly cost for a use case that can be handled with a simple subnet restriction. Azure Firewall is typically used for multi-tenant filtering or egress control, not to replace Service Endpoints for private PaaS connectivity from a specific gateway subnet.
- ✗
Use a site-to-site VPN between the App Service and Application Gateway.
Why it's wrong here
A site-to-site VPN is an IPsec tunnel designed to connect an on-premises network to a virtual network; it cannot be established from an App Service instance, which is a multi-tenant PaaS service and does not terminate VPN tunnels. The Application Gateway and App Service would already be in the same Azure region, so routing traffic through an on-premises VPN endpoint would add latency and complexity without any security benefit. This option conflates hybrid networking with intra-Azure connectivity and does not satisfy the access-restriction requirement.
Go deeper
Related to this question
Learn chapter
Conditional Access Policy Design
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.