Courseiva
Describe Azure architecture and servicesmediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure architecture and services Practice Question

A financial services company runs a critical trading application in its on-premises data center. The company is migrating some workloads to Azure and requires a dedicated, private network connection between its on-premises network and Azure. The connection must not use the public internet, must provide consistent latency and higher bandwidth than a typical internet-based VPN, and must be backed by a service-level agreement (SLA) for availability. Which Azure service should the company use to meet these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse Azure VPN Gateway with ExpressRoute because both provide connectivity, but they fail to recognize that ExpressRoute is the only option that bypasses the public internet and offers a guaranteed SLA for availability and consistent latency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ExpressRoute

ExpressRoute is the correct choice because it provides a dedicated, private connection between on-premises networks and Azure that bypasses the public internet entirely. This ensures consistent latency, higher bandwidth options (up to 100 Gbps), and a financially backed SLA of at least 99.95% availability, meeting all the stated requirements for a critical trading application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway creates an encrypted tunnel over the public internet. While it provides a secure connection, it does not offer a private connection that bypasses the public internet, and bandwidth and latency are typically lower and less consistent than ExpressRoute.

  • ExpressRoute

    Why this is correct

    ExpressRoute is the correct choice because it provides a dedicated, private connection between your on-premises network and Azure, completely bypassing the public internet. This delivers higher and more consistent bandwidth, lower and predictable latency, and an availability SLA — all critical for a latency-sensitive trading application. The connection is established through a service provider over a private MPLS circuit, ensuring that traffic never traverses the public internet, which also enhances security and reliability.

  • Azure Firewall

    Why it's wrong here

    Azure Firewall is a managed, cloud-native network security service that filters and inspects traffic within or to an Azure virtual network, enforcing security and compliance rules. It does not provide any form of connectivity or data-plane linking between your on-premises infrastructure and Azure; rather, it sits in front of workloads to protect them from inbound and outbound threats. Think of it as a security gateway that operates on top of an existing network path, not as a substitute for a private or encrypted connection. Therefore, it cannot meet the stated requirement of establishing a high-performance, private site-to-site link.

    When this WOULD be correct

    An exam question asks: 'A company needs to centrally inspect and filter all traffic between Azure virtual networks and the internet. Which service should they deploy?' In that scenario, Azure Firewall is the correct answer.

  • Azure Front Door

    Why it's wrong here

    Azure Front Door is a global load balancer and content delivery network that operates over the public internet. It is designed for web applications and does not provide a private dedicated connection between an on-premises network and Azure.

    When this WOULD be correct

    A company needs to deliver applications globally with low latency, automatic failover, and SSL offloading, and requires a web application firewall (WAF) to protect against common web exploits. Azure Front Door would be the correct choice for global load balancing and acceleration of web applications.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

ExpressRouteCorrect answer

Why this is correct

ExpressRoute is the correct choice because it provides a dedicated, private connection between your on-premises network and Azure, completely bypassing the public internet. This delivers higher and more consistent bandwidth, lower and predictable latency, and an availability SLA — all critical for a latency-sensitive trading application. The connection is established through a service provider over a private MPLS circuit, ensuring that traffic never traverses the public internet, which also enhances security and reliability.

Azure FirewallWrong answer — click to see why

Why this is wrong here

Azure Firewall is a network security service that filters traffic, not a dedicated private connectivity solution. It does not provide a private, high-bandwidth, SLA-backed connection between on-premises and Azure.

★ When this WOULD be the correct answer

An exam question asks: 'A company needs to centrally inspect and filter all traffic between Azure virtual networks and the internet. Which service should they deploy?' In that scenario, Azure Firewall is the correct answer.

Why candidates choose this

Candidates may confuse 'firewall' with 'network connectivity' because both involve network-level control, or they think a firewall is required for private connections.

Azure Front DoorWrong answer — click to see why

Why this is wrong here

Azure Front Door is a global load balancer and application delivery controller that operates over the public internet, not a dedicated private connection. It does not provide a private, dedicated network link with consistent latency and bandwidth guarantees like ExpressRoute.

★ When this WOULD be the correct answer

A company needs to deliver applications globally with low latency, automatic failover, and SSL offloading, and requires a web application firewall (WAF) to protect against common web exploits. Azure Front Door would be the correct choice for global load balancing and acceleration of web applications.

Why candidates choose this

Candidates may confuse Front Door's global reach and performance benefits with the dedicated private connectivity of ExpressRoute, or think that 'Front Door' implies a direct network entry point similar to a private connection.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.