AZ-305 - Design Infrastructure Solutions - Section 4.4

Design network solutions including hub-and-spoke topologies, hybrid connectivity, and network security.

Design hub-and-spoke and Azure Virtual WAN topologies for connectivity between virtual networks, on-premises sites, and remote users, using Azure ExpressRoute or VPN Gateway for hybrid links. Integrate Azure Firewall and DDoS Protection to enforce network security boundaries and protect public-facing workloads.

hub-and-spokeAzure Virtual WANAzure ExpressRouteVPN GatewayAzure Firewall and DDoS Protection

Practice question for this objective

Free sampleDesign Infrastructure Solutionsmedium

A multinational has two ExpressRoute circuits, one in Amsterdam and one in Singapore, terminating in Microsoft Enterprise Edge routers. It wants the two on-premises datacenters to exchange data with each other over the Microsoft backbone without traversing the public internet, while keeping each circuit on the Standard SKU. Which capability is required?

  • AUpgrade both circuits to the ExpressRoute Premium add-on for global reachability.
  • BConfigure VPN Gateway with a VNet-to-VNet connection between two regional gateways.
  • CDeploy a Virtual WAN Basic with both ExpressRoute circuits attached to one hub.
  • DEnable ExpressRoute Global Reach between the Amsterdam and Singapore circuits. Correct
Global Reach links on-premises sites through Microsoft's network using two ExpressRoute circuits; Premium add-on solves a different problem (global Azure reachability from a single circuit). ExpressRoute Global Reach is the documented feature for exchanging data between on-premises sites through the Microsoft backbone, using two existing ExpressRoute circuits. The Standard SKU is sufficient when Global Reach is enabled.

Why A is wrong: Premium expands Azure region reachability across geopolitical boundaries from a single circuit; it does not link two on-premises sites to each other through the Microsoft backbone. Global Reach is the dedicated feature.

Why B is wrong: VNet-to-VNet links virtual networks in Azure, not on-premises sites; it also runs over the public internet for cross-region traffic if a hub is not introduced.

Why C is wrong: Basic Virtual WAN supports only site-to-site VPN; it does not accept ExpressRoute circuits, so this is not a valid composition.

Why D is correct: Correct. ExpressRoute Global Reach is the documented feature for exchanging data between on-premises sites through the Microsoft backbone, using two existing ExpressRoute circuits.

See more AZ-305 practice questions, answers explained.

More in this domain

Back to all Design Infrastructure Solutions objectives, or the AZ-305 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.