AZ-305 Design infrastructure solutions Practice Question
Your organization is migrating a legacy application to Azure that requires Windows authentication and a fixed IP address. The application will run on an Azure VM. You need to design a networking solution that ensures the VM retains its IP address even after a reboot and that the application can be reached by on-premises users using its hostname. Which TWO actions should you take? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse a static public IP with a static private IP, assuming external reachability requires a public IP, when in fact the question specifies on-premises users (likely over a VPN or ExpressRoute) and hostname resolution via a private DNS zone.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a static private IP address to the VM's NIC
A is correct because assigning a static private IP address to the VM's NIC ensures the IP address persists across reboots, which is required for Windows authentication and legacy application dependencies that rely on a fixed IP. This is done by setting the private IP allocation method to 'Static' in the NIC's IP configuration, preventing DHCP from assigning a new address after a restart.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign a static private IP address to the VM's NIC
Why this is correct
In Azure, a VM's private IP can be dynamic by default, meaning it may change when the VM is deallocated/restarted, breaking configuration that references the IP. Assigning a static private IP to the NIC guarantees a consistent address within the virtual network, which is critical for on-premises applications that connect via VPN/ExpressRoute and rely on a fixed endpoint. Additionally, static private IPs are managed at the NIC level and remain assigned until explicitly removed, supporting reliable name-to-IP mapping and firewall rules.
- ✗
Assign a static public IP address to the VM
Why it's wrong here
A public IP is used for internet-facing communication, but the scenario involves on-premises users connecting over VPN/ExpressRoute, which traverses the private address space. Even with a public IP, the VM's private IP would remain dynamic, so the application's name resolution and connectivity issues would persist. Moreover, exposing a public IP on the VM introduces unnecessary security risk, as it broadens the attack surface without solving the fixed-address requirement.
- ✗
Configure Azure Firewall to forward DNS requests
Why it's wrong here
Azure Firewall's DNS proxy is an optional feature that forwards DNS queries to a specified upstream DNS server, but it does not create or manage DNS records. In this scenario, name resolution should be handled by an Azure DNS private zone linked to the virtual network, which provides authoritative answers for the VM's hostname. The firewall's DNS proxy would only be relevant if you needed to intercept or redirect DNS traffic, which is not required for resolving a private zone record.
- ✓
Create an Azure DNS private zone and add an A record for the VM
Why this is correct
An Azure DNS private zone provides authoritative name resolution within a virtual network and can be linked to the network used by the VPN/ExpressRoute connection, allowing on-premises users to resolve the VM's hostname. By adding an A record that maps the hostname to the VM's static private IP, you ensure consistent, private DNS resolution that works alongside the fixed IP address. This combination is a best practice for hybrid environments: the private zone controls name resolution, while the static IP ensures the record never points to a stale address.
- ✗
Connect to the VM using Azure Bastion for name resolution
Why it's wrong here
Azure Bastion is a PaaS service that gives secure, browser-based RDP/SSH access to VMs without exposing public IPs, but it is entirely unrelated to DNS or name resolution. Using Bastion would not help on-premises users resolve the VM's hostname; it merely facilitates an interactive administrative session to the VM's private IP. Therefore, it neither addresses the need for a fixed IP nor for DNS records, making it an incorrect solution to the stated problem.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.