AZ-305 Design infrastructure solutions Practice Question
Your company has an Azure subscription with multiple virtual networks (VNets) in different regions. You need to ensure that resources in all VNets can communicate with each other privately over the Microsoft backbone network. Which Azure solution should you implement?
⚠ Common exam trap
Many exam-takers confuse VNet peering with VPN Gateway, assuming a VPN is required for private connectivity, but VNet peering provides direct private connectivity over the Microsoft backbone without any public internet exposure or gateway overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VNet peering
VNet peering connects Azure virtual networks privately over the Microsoft backbone network, enabling resources in different VNets (including those in different regions) to communicate directly without traversing the public internet. It uses the Azure infrastructure to route traffic between peered VNets with low latency and high bandwidth, meeting the requirement for private inter-VNet communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VNet peering
Why this is correct
VNet peering establishes one-to-one connectivity between two Azure virtual networks over Microsoft's private backbone, allowing resources in separate VNets to communicate using private IP addresses without any public internet traversal, gateways, or extra cost per flow. This is the native Azure solution for inter-VNet connectivity because it is direct, unilateral, and supports both regional and global peering, making it the correct choice for joining spoke VNets to a hub or linking peered environments.
- ✗
Azure ExpressRoute
Why it's wrong here
Azure ExpressRoute creates a dedicated, private connection between your on-premises datacenter and Azure, bypassing the public internet, but it is not designed to directly interconnect two VNets. While you can attach multiple VNets to an ExpressRoute circuit to reach each other through the Microsoft edge, that requires additional gateway configuration and is not the same low-latency, direct VNet-to-VNet peering relationship. Therefore it is not the correct answer.
- ✗
Azure DNS
Why it's wrong here
Azure DNS is a hosting service for DNS domains, providing name resolution and record management, but it has no role in forwarding data packets between virtual networks. It operates at the application layer, translating names to IP addresses, whereas the cross-VNet connectivity question requires a data-plane path. Since DNS does not create a network link, it cannot possibly satisfy the requirement and is wrong.
- ✗
Azure VPN Gateway
Why it's wrong here
Azure VPN Gateway, while capable of connecting VNets through an IPsec/IKE tunnel between gateway subnets, does so by sending encrypted traffic over the public internet and introduces gateway overhead, latency, and throughput limits. It is fundamentally a VPN solution for site-to-site and point-to-site scenarios, not a direct peering mechanism, and would be an unnecessarily complex and inferior alternative to VNet peering for inter-VNet traffic. Hence it is not the correct answer.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.