AZ-305 Design infrastructure solutions Practice Question
You need to design a networking solution for a multi-tier application that includes a web front-end, an API layer, and a database. The web and API tiers must be accessible from the internet, while the database tier must be isolated. What is the most secure and efficient design?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing separate VNets (Option B) thinking it provides better isolation, but they overlook that a single VNet with separate subnets and NSGs is simpler, lower latency, and equally secure for multi-tier applications within the same trust boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy all tiers in the same VNet with separate subnets, and use NSGs to restrict traffic. Place an Azure Application Gateway with WAF in front of the web tier.
It uses a single VNet with separate subnets for each tier, allowing Network Security Groups (NSGs) to enforce micro-segmentation and restrict traffic between tiers. The Azure Application Gateway with Web Application Firewall (WAF) provides Layer 7 protection and SSL termination for internet-facing web traffic, while the database tier remains isolated with no public endpoint. This design minimizes latency by keeping all tiers within the same VNet and avoids the complexity of VNet peering or unnecessary firewall inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place all VMs in the same subnet and use a single Azure Load Balancer to distribute traffic.
Why it's wrong here
This design eliminates any network segmentation between application and database tiers, so an attacker who compromises the web tier can directly reach backend databases on open ports, and a single public-facing load balancer exposes all VMs to the internet, including the data tier. An Azure Load Balancer (L4) only performs TCP/UDP distribution; it cannot provide layer-7 filtering, URL routing, or web application firewall protection, and it gives no mechanism to restrict traffic between tiers within the same subnet.
- ✗
Use separate VNets for each tier and connect them with VNet peering.
Why it's wrong here
Creating a separate VNet for each tier and interconnecting them with VNet peering introduces unnecessary overhead: peering is non-transitive, so you must manage multiple peering connections and complex network security groups across VNets, and you cannot leverage a single Azure Application Gateway in front of all tiers without additional hub infrastructure. Subnets inside one VNet already provide isolation with full control via NSGs and allow an application gateway to sit in the same VNet, giving the same security benefit at far lower complexity and cost.
- ✗
Deploy all VMs in a single subnet and use Azure Firewall to inspect all inbound and outbound traffic.
Why it's wrong here
Placing every VM in a single subnet collapses compartmentalization and forces Azure Firewall to act as a central inspection point for all traffic if you add complex user-defined routes; however, Azure Firewall is a managed stateful network firewall, not a substitute for subnet isolation, so you lose the ability to apply different NSG policies per tier and you incur significant cost for features that could be handled by simpler subnet-level NSGs. Furthermore, Azure Firewall does not provide web application firewall capabilities, so you still need an Application Gateway or other WAF device, making this design both expensive and architecturally flawed.
- ✓
Deploy all tiers in the same VNet with separate subnets, and use NSGs to restrict traffic. Place an Azure Application Gateway with WAF in front of the web tier.
Why this is correct
This architecture separates each application tier into its own subnet and applies per-subnet NSG rules to allow only required communication (e.g., web-to-app on port 443, app-to-data on port 3306), ensuring that a compromise in one tier does not implicitly expose another. An Azure Application Gateway with its WAF sits in a dedicated gateway subnet, providing the single internet-facing HTTPS endpoint, SSL offload, cookie-based session affinity, path-based routing, and OWASP Top-10 protection—all before traffic reaches the web tier. This is the recommended pattern because it balances security and operational simplicity.
Visual reference
Go deeper
Related to this question
Learn chapter
Multi-Region Active-Active Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.