AZ-305 Design infrastructure solutions Practice Question
You need to design a virtual network architecture for a three-tier application in Azure. The web tier must be accessible from the internet, the application tier must only be accessible from the web tier, and the database tier must only be accessible from the application tier. Which combination of Azure services should you use?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Front Door with Application Gateway, or assume that service endpoints alone provide the same level of isolation as Private Endpoints, but service endpoints do not remove public endpoint exposure and cannot enforce subnet-to-subnet access control without additional NSG rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Application Gateway with WAF, network security groups (NSGs) on subnets, and Azure Private Endpoints for the database.
It uses Azure Application Gateway with WAF to provide internet-facing, layer-7 web traffic management and protection, network security groups (NSGs) on subnets to enforce east-west traffic isolation (web-to-app, app-to-database), and Azure Private Endpoints for the database to ensure the database is accessible only via a private IP within the virtual network, eliminating exposure to the internet. This combination meets the three-tier isolation requirements precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Front Door, service endpoints, and Azure SQL Database with firewall rules.
Why it's wrong here
Azure Front Door is a global Layer 7 CDN/load balancer, not a regional gateway designed for a single three-tier application; it adds unnecessary latency and cost unless you need multi-region web acceleration. Service endpoints for Azure SQL Database still rely on the database's public endpoint and only restrict source IPs to the VNet, leaving the service vulnerable to data exfiltration if a compromised resource inside the VNet is able to reach it. Firewall rules on the SQL logical server complement service endpoints but do not replace Private Endpoints, which attach a private NIC to the VNet and remove public exposure entirely. Therefore, this architecture fails to meet the security and segmentation requirements of a private three-tier application.
- ✓
Use Azure Application Gateway with WAF, network security groups (NSGs) on subnets, and Azure Private Endpoints for the database.
Why this is correct
Azure Application Gateway with WAF provides the required Layer 7 internet-facing ingress, offering TLS offload, path-based routing, and OWASP Top 10 protection, which is superior to a simple load balancer for a three-tier app. Network security groups (NSGs) applied to each subnet establish explicit allow/deny rules between the web, application, and data tiers, enabling least-privilege communication and preventing lateral movement if one tier is compromised. Azure Private Endpoints for the database place the Azure SQL Database into the VNet with a private IP address, ensuring traffic never traverses the public internet and can be further secured with NSGs on the subnet or with Network Security Perimeter controls. This combination of L7 WAF protection, subnet segmentation, and private connectivity is the industry best practice for a secure three-tier architecture on Azure.
- ✗
Use Azure Load Balancer, Azure Firewall, and Azure SQL Database with public endpoint.
Why it's wrong here
Azure Load Balancer operates at Layer 4 only, providing NAT and distribution rules over TCP/UDP without any awareness of HTTP paths or application-level inspection; it cannot protect against SQL injection or other web application attacks the way WAF does. Azure Firewall is a stateful network firewall that can enforce east-west and north-south rules, but it does not replace NSGs for fine-grained subnet-level filtering, and without a WAF the web tier remains exposed to application-layer threats. Exposing the Azure SQL Database via a public endpoint is a fundamental security anti-pattern because it makes the database reachable from the internet, forcing reliance on firewall IP rules that are static and often misconfigured. Consequently, this design lacks both required L7 protection for the web front end and private, secure connectivity to the data tier.
- ✗
Use a single virtual network with three subnets, no NSGs, and Azure SQL Database with VNet injection.
Why it's wrong here
Creating a single virtual network with three subnets and no NSGs removes all traffic filtering between tiers, allowing any resource in the web tier to freely communicate with the data tier, which violates the security principle of least privilege and greatly increases the blast radius of a compromised VM. VNet injection is supported for Azure SQL Managed Instance, but not for standard Azure SQL Database elastic pools or single databases; standard SQL Database uses logical server connectivity and cannot be directly injected into a subnet, so this premise is technically invalid. If you attempt to use this pattern without NSGs or a network virtual appliance, there is no mechanism to enforce security rules, and the database may inadvertently be exposed via service endpoints or firewall misconfigurations. Thus, the design lacks both the required traffic control and the correct PaaS connectivity model, making it unsuitable for a production three-tier environment.
Visual reference
Go deeper
Related to this question
Learn chapter
Designing Application Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.