Courseiva

AZ-305 Design infrastructure solutions Practice Question

You are designing a network architecture for a three-tier application in Azure. The web tier must be accessible from the internet. The application tier must only accept traffic from the web tier. The database tier must only accept traffic from the application tier. Which TWO Azure services should you use to enforce these network rules? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates choose Azure Firewall (Option E) for all network security needs, overlooking that NSGs are the native, lightweight solution for east-west traffic filtering within a virtual network, and Azure Firewall is typically reserved for centralized inspection, logging, and outbound traffic control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network Security Groups (NSGs)

Network Security Groups (NSGs) are the correct choice because they act as a distributed, stateful firewall that can filter traffic at the subnet or NIC level using source and destination IP addresses, ports, and protocols. By applying NSGs to the subnets hosting the application and database tiers, you can create inbound rules that restrict traffic to only the preceding tier's subnet or IP range, enforcing the required east-west segmentation without introducing additional latency or cost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion is a platform-managed PaaS service that provides secure RDP and SSH access to virtual machines through the Azure portal, using a private IP address on the target VM and eliminating public exposure of management ports. It operates at the management/control plane and is not a data-plane traffic filter, so it cannot inspect or restrict east-west traffic between the web, application, and data subnets. Because it enforces no network ACLs or segmentation rules, it does not satisfy the requirement for inter-tier isolation.

  • ✓

    Network Security Groups (NSGs)

    Why this is correct

    Network Security Groups are stateful, distributed packet filters applied at a subnet or network interface (NIC) level, with rules that allow or deny traffic based on source/destination IP, port, endpoint, and protocol. For a three-tier application, you can associate a distinct NSG with each subnet—for example, the web subnet allows HTTPS from the internet or Application Gateway, the application subnet allows only a specific port from the web subnet, and the data subnet allows only the database port from the application subnet. This implements least-privilege segmentation directly within the VNet at no additional cost and without introducing a centralized appliance or extra network hop.

  • ✓

    Azure Application Gateway

    Why this is correct

    Azure Application Gateway is a crucial service for this scenario as it operates at Layer 7 (HTTP/HTTPS) and can expose the web tier to the internet via a public IP address. It acts as a reverse proxy and load balancer, distributing incoming internet traffic to the web servers. This directly satisfies the constraint that "The web tier must be accessible from the internet," while also offering features like Web Application Firewall (WAF) to protect against common web vulnerabilities.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global Layer 7 (HTTP/HTTPS) load balancer and application delivery service that routes user traffic to the healthiest origin endpoint to improve performance and availability. Its security capabilities, such as Web Application Firewall and bot protection, are edge-focused and protect the application entry point, not the traffic crossing subnets inside a virtual network. Front Door has no mechanism to enforce ACLs or filter traffic between the web, application, and data tiers, so it does not solve the internal isolation requirement.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a centralized, stateful firewall-as-a-service that provides inbound/outbound network filtering, DNAT, and FQDN-based rules, typically deployed in a hub VNet. While it could technically filter traffic between tiers if placed inline, using it for a simple three-tier application adds unnecessary cost, operational overhead, and a hairpin hop for every cross-tier packet. Native NSGs are the simpler, lower-latency control for basic tier isolation; Azure Firewall is more appropriate for enterprise environments requiring centralized policy management, high-level egress filtering, or advanced auditing.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.