AZ-305 Design infrastructure solutions Practice Question
You are designing a network topology for a global e-commerce company that operates multiple web applications. The company has three main offices (New York, London, Tokyo) connected via ExpressRoute to Azure. Users access the applications through a public endpoint. The company requires that traffic be routed to the nearest healthy application instance based on geographic location, and that the solution provide automatic failover if an entire region goes down. Additionally, the company wants to protect against DDoS attacks at the network layer. You need to recommend a solution that meets these requirements while minimizing cost. What should you include in the design?
⚠ Common exam trap
Many exam-takers confuse Azure Traffic Manager with Azure Front Door, assuming Traffic Manager's geographic routing and DNS-level failover are sufficient, but they overlook that Traffic Manager lacks built-in DDoS protection and application-layer features, and that Front Door provides a more cost-effective all-in-one solution for global load balancing with DDoS protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Azure Front Door with geographic routing and enable DDoS protection.
Azure Front Door with geographic routing directs users to the nearest healthy application instance based on geographic location, and it provides automatic failover if an entire region goes down by routing traffic to the next closest healthy region. Front Door also includes built-in DDoS protection at the network layer (Azure DDoS Basic) at no additional cost, which meets the DDoS requirement while minimizing cost. This combination satisfies all requirements without the need for separate, more expensive services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy Azure Front Door with geographic routing and enable DDoS protection.
Why this is correct
Azure Front Door is the correct choice for a global e-commerce topology because it operates as a single anycast global endpoint, automatically routing users to the nearest region via its distributed edge network. It natively supports geographic routing to enforce data residency or direct customer traffic based on country/region, and it integrates with Azure WAF and Azure DDoS Standard, providing both L7 and L3/L4 protection at the edge. This combination gives you global load balancing, low-latency access, and comprehensive security without needing to manage per-region ingress gateways.
- ✗
Deploy Azure Firewall in each region and use Public IP prefix for egress.
Why it's wrong here
Deploying Azure Firewall in each region with a Public IP prefix is flawed because Azure Firewall is a regional, stateful security service that inspects network traffic but does not perform global load balancing or geographic routing. While a Public IP prefix ensures predictable outbound egress IPs, it does not solve inbound traffic distribution across regions. This architecture would still require an external DNS or global load balancer to route users, and it lacks the anycast edge capabilities and integrated DDoS protection that a global entry point like Front Door provides.
- ✗
Deploy Azure Application Gateway v2 with WAF in each region and Azure DDoS Standard protection.
Why it's wrong here
Azure Application Gateway v2 with WAF is a regional Layer 7 load balancer, so even if you deploy one in each region, you must rely on separately configured DNS records or an additional global traffic manager to send users to the correct regional gateway. It does not offer anycast or a single global DNS name for the entire topology, and its geographic routing capabilities are limited to routing within a virtual network, not across regions. Azure DDoS Standard protection is also scoped to a specific public IP in a VNet, not global, so this option fails to provide a unified global edge with DDoS protection at the internet boundary.
- ✗
Deploy Azure Traffic Manager with geographic routing and Azure DDoS Standard protection.
Why it's wrong here
Azure Traffic Manager is a DNS-based global load balancer that does support geographic routing, but it lacks native DDoS protection because it only resolves DNS names and does not proxy traffic—the actual payload still flows directly to your origin IPs, which remain exposed to L3/L4 DDoS attacks. Additionally, because routing is DNS-dependent, failover is delayed by TTL caching and health probe intervals, and geographic routing policies are applied at DNS resolution time, not per-request, making it less responsive and less secure. This option does not meet the requirement for a secure, globally load-balanced edge with built-in DDoS mitigation, which Front Door provides.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.