AZ-305 Design infrastructure solutions Practice Question
You are designing a network topology for a multi-tier application in Azure. The application has a web tier, an API tier, and a database tier. You need to ensure that the web tier can communicate with the API tier, and the API tier can communicate with the database tier, but the web tier cannot directly access the database tier. Which Azure networking solution should you implement?
⚠ Common exam trap
AZ-305 often tests whether candidates confuse ASGs (application-tier grouping for NSG rules) with service tags (Azure platform service IP ranges), leading them to pick NSGs with service tags when role-based micro-segmentation is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Security Groups (ASGs)
Azure Application Security Groups (ASGs) let you group VMs by workload role (web, API, database) and then write NSG rules that reference those groups as source and destination, so you can allow web-to-API and API-to-database while implicitly denying web-to-database. This provides the tiered, role-based segmentation the scenario requires without managing individual IP addresses. ASGs are the purpose-built Azure construct for application-centric micro-segmentation within a VNet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a centralized firewall but is more expensive and complex than needed.
- ✗
Network Security Groups (NSGs) with service tags
Why it's wrong here
NSGs can filter traffic but managing rules for each tier can become complex.
- ✓
Azure Application Security Groups (ASGs)
Why this is correct
ASGs allow you to group VMs and define security rules based on application tiers, simplifying policy management.
- ✗
VNet peering
Why it's wrong here
VNet peering connects separate VNets, not control traffic between subnets in the same VNet.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.