Azure Networking Architecture Design Flashcards
6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Networking Architecture Design flashcards as text
You need to design connectivity between 10 Azure virtual networks so that any VNet can communicate with any other VNet with minimal management overhead. Which design is recommended?
Answer: Use a hub-and-spoke topology with Azure Virtual WAN
Azure Virtual WAN provides a hub-and-spoke managed network that supports any-to-any connectivity without requiring full-mesh VNet peering.
A workload requires that all outbound internet traffic from Azure VMs be inspected by a firewall before leaving Azure. Which service should you deploy in the hub VNet?
Answer: Azure Firewall
Azure Firewall is a managed, stateful network security service that can inspect and filter all outbound traffic using FQDN-based and network rules.
Your application requires that Azure PaaS services like Azure SQL Database be accessible only from within your VNet and not over the public internet. Which feature should you use?
Answer: Private Endpoints
Private Endpoints assign a private IP from your VNet to a PaaS service, making it accessible only from your VNet while the public endpoint can be disabled.
You need to connect an on-premises datacenter to Azure with a guaranteed bandwidth SLA, low latency, and private connectivity not traversing the internet. Which option should you recommend?
Answer: Azure ExpressRoute
ExpressRoute provides dedicated private connectivity between on-premises and Azure through a connectivity provider with an SLA-backed bandwidth guarantee.
A global application needs to route users to the nearest healthy Azure region and perform SSL offloading. Which Azure service is best suited?
Answer: Azure Front Door
Azure Front Door is a global anycast CDN and load balancer that provides SSL offloading, WAF, and latency-based routing to the nearest healthy origin.
You need to inspect and control traffic flowing between spoke VNets in a hub-and-spoke architecture. What must you configure in addition to deploying Azure Firewall in the hub?
Answer: User-Defined Routes (UDRs) to redirect spoke traffic through the firewall
UDRs (custom route tables) on spoke subnets must point the next hop to the Azure Firewall private IP to force traffic through inspection.