Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your company deploys a line-of-business application on Azure App Service. The application requires custom domain names and SSL/TLS certificates. You need to ensure that the application can be accessed via a custom domain with HTTPS. What should you configure in the App Service?

⚠ Common exam trap

Many exam-takers confuse IP restrictions (which filter traffic) or deployment slots (which manage releases) with the necessary steps for custom domain and certificate binding, leading them to overlook the direct requirement of adding the domain and binding the certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the custom domain and bind the SSL/TLS certificate.

To access an App Service via a custom domain with HTTPS, you must first add the custom domain to the App Service and then bind an SSL/TLS certificate (either App Service Managed Certificate, a Key Vault certificate, or a third-party certificate) to that domain. This binding enables the App Service to present the certificate during the TLS handshake, allowing secure HTTPS connections. Without both steps, the custom domain will not resolve securely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the custom domain and bind the SSL/TLS certificate.

    Why this is correct

    Azure App Service web apps require a custom domain to be mapped to the app's default hostname (e.g., appname.azurewebsites.net) before users can reach it via a domain they own. Binding an SSL/TLS certificate (whether App Service Managed Certificate, Key Vault, or a custom PFX) then enables HTTPS for that domain, fulfilling the need for secure access over the company's domain. Without both steps, the app stays on the azurewebsites.net hostname with only the default wildcard certificate, so the custom domain remains inaccessible over HTTPS.

  • ✗

    Configure IP restrictions to allow only the custom domain.

    Why it's wrong here

    IP restrictions in Azure App Service are an access-control feature that filters incoming requests by the client's source IP address range, not by the domain name in the request. They do not perform DNS mapping or certificate binding, so a request to the default *.azurewebsites.net hostname can still be permitted if the source IP is allowed. 'Allow only the custom domain' is not possible—IP Restrictions operate on the network layer, whereas custom domain configuration requires Host-header validation.

  • ✗

    Create a deployment slot for production traffic.

    Why it's wrong here

    Deployment slots are separate live environments (e.g., staging, QA) that share the same App Service plan and follow a slotname-appname.azurewebsites.net hostname pattern, intended for testing releases and swapping them into production. Creating a slot for production traffic does not alter the existing custom domain mapping or the SSL/TLS binding on the current production endpoint; it only gives you an additional hostname to which you'd still need to apply the domain and certificate. Slot swapping is a deployment mechanism, not a domain-or-TLS configuration feature.

  • ✗

    Scale out the App Service plan to increase instance count.

    Why it's wrong here

    Scaling out adds worker instances to the App Service plan to handle increased load or enable autoscale, which affects capacity, isolation, and availability but leaves the front-end hostname, DNS records, and TLS bindings completely unchanged. The application remains reachable only through the currently configured domains with their existing certificates, so this action has no bearing on enabling HTTPS on a custom domain. Performance and scale decisions are independent from domain and security configuration.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.