AZ-305 Design infrastructure solutions Practice Question
You are designing a network architecture for a three-tier application hosted in Azure. The front-end tier must be accessible from the internet, the business tier must only communicate with the front-end tier, and the data tier must only communicate with the business tier. You need to minimize exposure and use Azure-native services. Which combination of services should you use?
⚠ Common exam trap
Many candidates confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7) and overlook the need for WAF to protect internet-facing web applications, or they incorrectly assume VPN Gateway or Azure Firewall can serve as a front-end load balancer for HTTP traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway with WAF for front-end, NSGs on subnets, and service endpoints
Azure Application Gateway with WAF provides Layer 7 HTTP/HTTPS load balancing and web application firewall protection for internet-facing front-end traffic. Network Security Groups (NSGs) on subnets enforce east-west traffic isolation, allowing the business tier to only receive traffic from the front-end subnet and the data tier to only receive traffic from the business subnet. Service endpoints secure access to PaaS data services (e.g., Azure SQL Database) from the data tier subnet without exposing public endpoints, meeting the requirement to minimize exposure using Azure-native services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Load Balancer for front-end, NSGs on subnets, and VNet peering
Why it's wrong here
A public Azure Load Balancer operates only at Layer 4 (TCP/UDP), distributing raw traffic without any TLS inspection, path-based routing, or web application firewall (WAF) capabilities; it cannot protect the front-end from application-layer attacks such as SQL injection or cross-site scripting. NSGs can segment subnets, but VNet peering is designed to connect virtual networks, not to secure or expose a public-facing web tier. Thus, this combination lacks the HTTP/HTTPS-aware protection required for a three-tier web application.
- ✗
VPN Gateway for front-end, NSGs on subnets, and private endpoints
Why it's wrong here
Azure VPN Gateway is built for encrypted site-to-site or point-to-site IPSec tunnels between on-premises networks and Azure; it is not a reverse proxy, load balancer, or public internet-facing entry point for web traffic. Private endpoints are used to consume Azure PaaS services privately from a VNet, not to expose an application's front-end to external users, and they provide no HTTP routing or WAF functionality. Forcing internet customers to establish a VPN tunnel is impractical and contradicts the goal of a publicly accessible three-tier web app.
- ✓
Azure Application Gateway with WAF for front-end, NSGs on subnets, and service endpoints
Why this is correct
Azure Application Gateway is a Layer-7 load balancer with an integrated web application firewall (WAF), delivering TLS termination, cookie-based session affinity, URL path-based routing, and OWASP Top-10 attack protection for the front-end HTTP/HTTPS tier. NSGs placed on each subnet enforce east-west traffic rules so the web tier can only communicate with the app tier, which can only reach the data tier. Service endpoints restrict Azure PaaS services like SQL Database and Storage to traffic from a specific VNet subnet, adding a hardened network boundary for the backend. This combination fully aligns with a secured, tiered web architecture.
- ✗
Azure Firewall for all inbound traffic, NSGs on subnets, and VNet peering
Why it's wrong here
Azure Firewall is a stateful network and application (FQDN) firewall that provides central rule enforcement and threat intelligence, but it lacks the web-specific capabilities required for a front-end tier—such as TLS termination, HTTP path routing, session stickiness, and managed WAF rulesets to block SQL injection and XSS. Routing all inbound web traffic through a single Azure Firewall creates a performance bottleneck and makes costs unjustifiably high for a load-balanced public web workload. While NSGs on subnets add useful segmentation, adding VNet peering does not solve the lack of Layer-7 web protection, so this design is mismatched for the application's requirements.
Visual reference
Go deeper
Related to this question
Learn chapter
Designing Compute Solutions
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.