Courseiva

AZ-305 Design infrastructure solutions Practice Question

You are designing a network topology for a multi-tier application in Azure. The application has a web tier, an API tier, and a database tier. You need to ensure that the web tier can communicate with the API tier, and the API tier can communicate with the database tier, but the web tier cannot directly access the database tier. Which Azure networking solution should you implement?

⚠ Common exam trap

AZ-305 often tests whether candidates confuse ASGs (application-tier grouping for NSG rules) with service tags (Azure platform service IP ranges), leading them to pick NSGs with service tags when role-based micro-segmentation is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Application Security Groups (ASGs)

Azure Application Security Groups (ASGs) let you group VMs by workload role (web, API, database) and then write NSG rules that reference those groups as source and destination, so you can allow web-to-API and API-to-database while implicitly denying web-to-database. This provides the tiered, role-based segmentation the scenario requires without managing individual IP addresses. ASGs are the purpose-built Azure construct for application-centric micro-segmentation within a VNet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a centralized firewall but is more expensive and complex than needed.

  • ✗

    Network Security Groups (NSGs) with service tags

    Why it's wrong here

    NSGs can filter traffic but managing rules for each tier can become complex.

  • ✓

    Azure Application Security Groups (ASGs)

    Why this is correct

    ASGs allow you to group VMs and define security rules based on application tiers, simplifying policy management.

  • ✗

    VNet peering

    Why it's wrong here

    VNet peering connects separate VNets, not control traffic between subnets in the same VNet.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.