Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your company has a hybrid network with multiple on-premises sites connected to Azure via ExpressRoute. You need to design a DNS resolution strategy that allows Azure resources to resolve on-premises hostnames and on-premises clients to resolve Azure hostnames. The solution must minimize administrative overhead. What should you use?

⚠ Common exam trap

It's easy for candidates to confuse Azure DNS public zones with private DNS resolution, overlooking that conditional forwarding requires a DNS resolver or forwarder, not just a zone, and that Azure DNS Private Resolver is the managed service designed specifically for hybrid DNS scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure DNS Private Resolver

Azure DNS Private Resolver enables hybrid DNS resolution by forwarding DNS queries between on-premises networks and Azure virtual networks without requiring domain-joined VMs or custom DNS servers. It supports conditional forwarding to on-premises DNS servers via ExpressRoute, allowing Azure resources to resolve on-premises hostnames and vice versa, while minimizing administrative overhead through a managed service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion is a fully managed PaaS service that provides secure RDP and SSH connectivity to virtual machines directly through the Azure portal, terminating the remote desktop or SSH session at the browser. It is not a DNS component and has no role in query resolution or zone propagation; it cannot answer or forward hostname queries for private DNS names. Therefore, regardless of configuration, Bastion cannot connect on-premises networks to Azure DNS private zones.

  • ✗

    Azure DNS public zones with conditional forwarding

    Why it's wrong here

    Azure DNS public zones are authoritative solely for globally resolvable public DNS names, not for private hostnames assigned within Azure virtual networks. Conditional forwarding is a capability of on-premises DNS servers that forwards queries for foreign domains to a target DNS server or IP; however, Azure DNS public zones do not expose an inbound listener or resolver IP that on-premises can forward private-zone queries to. You would need a separate Azure-hosted resolver to bridge the two environments, making public zones an unsuitable replacement for hybrid DNS resolution.

  • ✓

    Azure DNS Private Resolver

    Why this is correct

    Azure DNS Private Resolver is the correct choice because it provides managed inbound and outbound DNS endpoints within an Azure virtual network, enabling bidirectional name resolution between on-premises infrastructure and Azure private DNS zones. An inbound endpoint gives on-premises DNS servers a fixed IP address for forwarding queries to Azure private zones, while an outbound endpoint with forwarding rulesets lets Azure query on-premises DNS for internal names. This service supports conditional forwarding natively and removes the need to deploy and patch custom DNS VMs, making it a truly hybrid-native resolution option.

  • ✗

    Azure Firewall DNS proxy

    Why it's wrong here

    Azure Firewall's DNS proxy is a pass-through feature that intercepts egress DNS traffic and forwards it to a user-specified DNS server, caching replies to reduce latency; it does not host zones, participate in conditional forwarding to Azure private DNS zones, or offer an on-premises reachable resolver endpoint. When used in a hybrid scenario, it would simply forward on-premises queries to a DNS server that cannot resolve private-zone hostnames and lacks the routing logic needed to identify private zones. Its operational scope is limited to the Azure firewall's network context and cannot mediate the two-way query flow required by the scenario.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.