AZ-900 Describe Azure architecture and services Practice Question
A small business is moving its on-premises web application to Azure. The IT administrator wants to deploy the application to a logically isolated network in the cloud, control inbound and outbound traffic with security rules, and connect the network back to the office over an encrypted tunnel. Which Azure service should the administrator use as the foundation for this design?
⚠ Common exam trap
The trap here is treating a load balancing or DNS service as the networking foundation, when those services must be deployed into a virtual network that already exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Virtual Network, which provides isolated network segments, subnets, and network security groups in Azure.
Azure Virtual Network is the core networking service in Azure, providing an isolated address space where subnets host resources such as virtual machines and PaaS endpoints. Network security groups attached to subnets or interfaces filter traffic with allow and deny rules, and VPN Gateway or ExpressRoute connects the virtual network to on-premises environments. The other services are traffic distribution or name resolution add-ons that require a virtual network to exist first.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure DNS, which hosts public and private DNS zones and resolves names for Azure resources.
Why it's wrong here
Azure DNS hosts DNS zones and provides name resolution, including private zones linked to virtual networks, but it does not create isolated network segments, apply traffic security rules, or establish encrypted tunnels. Name resolution is a supporting capability, and Azure DNS depends on a virtual network rather than replacing it as the networking foundation.
- ✗
Azure Application Gateway, which provides layer 7 load balancing and web application firewall capabilities.
Why it's wrong here
Application Gateway is a regional layer 7 load balancer with URL-based routing and optional Web Application Firewall, and it must be deployed into a subnet of an existing virtual network. It cannot itself create the isolated network or the encrypted tunnel to the office, so it addresses only part of the design and not the foundation.
- ✓
Azure Virtual Network, which provides isolated network segments, subnets, and network security groups in Azure.
Why this is correct
Azure Virtual Network is the fundamental building block for private networking in Azure, allowing subnets, network security groups, and connectivity options such as VPN Gateway. It establishes the isolated network boundary the administrator needs and is the scope where an encrypted site-to-site tunnel to the office would be attached, making it the correct foundation.
- ✗
Azure Load Balancer, which distributes incoming traffic across backend virtual machines for high availability.
Why it's wrong here
Azure Load Balancer distributes layer 4 traffic to backend pool members and health probes, but it does not create an isolated network, define subnets, or provide site-to-site connectivity. It is a traffic distribution service that would sit on top of a virtual network rather than serve as the networking foundation for this migration.
Visual reference
Go deeper
Related to this question
Learn chapter
Role-Based Access Control (RBAC)
Key term
Azure Virtual Network
Azure Virtual Network is a cloud service that lets you create a private, isolated network in the Microsoft Azure cloud, allowing your virtual machines and other resources to communicate securely with each other, the internet, and your on-premises network.
Key term
PaaS
Platform as a Service (PaaS) is a cloud computing model that provides a managed platform for developers to build, run, and manage applications without dealing with the underlying infrastructure.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.