AZ-305 - Design Infrastructure Solutions (38% of the exam) - Section 4.4

Design network solutions including hub-and-spoke topologies, hybrid connectivity, and network security.

Design hub-and-spoke and Azure Virtual WAN topologies for connectivity between virtual networks, on-premises sites, and remote users, using Azure ExpressRoute or VPN Gateway for hybrid links. Integrate Azure Firewall and DDoS Protection to enforce network security boundaries and protect public-facing workloads.

hub-and-spokeAzure Virtual WANAzure ExpressRouteVPN GatewayAzure Firewall and DDoS Protection

Practice question for this objective

Free sampleDesign Infrastructure Solutionsmedium

A multinational has two ExpressRoute circuits, one in Amsterdam and one in Singapore, terminating in Microsoft Enterprise Edge routers. It wants the two on-premises datacenters to exchange data with each other over the Microsoft backbone without traversing the public internet, while keeping each circuit on the Standard SKU. Which capability is required?

  • AUpgrade both circuits to the ExpressRoute Premium add-on for global reachability.
  • BConfigure VPN Gateway with a VNet-to-VNet connection between two regional gateways.
  • CDeploy a Virtual WAN Basic with both ExpressRoute circuits attached to one hub.
  • DEnable ExpressRoute Global Reach between the Amsterdam and Singapore circuits. Correct
Global Reach links on-premises sites through Microsoft's network using two ExpressRoute circuits; Premium add-on solves a different problem (global Azure reachability from a single circuit). ExpressRoute Global Reach is the documented feature for exchanging data between on-premises sites through the Microsoft backbone, using two existing ExpressRoute circuits. The Standard SKU is sufficient when Global Reach is enabled.

Why A is wrong: Premium expands Azure region reachability across geopolitical boundaries from a single circuit; it does not link two on-premises sites to each other through the Microsoft backbone. Global Reach is the dedicated feature.

Why B is wrong: VNet-to-VNet links virtual networks in Azure, not on-premises sites; it also runs over the public internet for cross-region traffic if a hub is not introduced.

Why C is wrong: Basic Virtual WAN supports only site-to-site VPN; it does not accept ExpressRoute circuits, so this is not a valid composition.

Why D is correct: Correct. ExpressRoute Global Reach is the documented feature for exchanging data between on-premises sites through the Microsoft backbone, using two existing ExpressRoute circuits.

See more AZ-305 practice questions, answers explained.

Exam traps in Design Infrastructure Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the AZ-305 bank for this domain.

  • Site-to-site VPN connections from on-premises devices to the hub.

    Why it is wrong: Basic Virtual WAN supports site-to-site VPN connections; this capability is not Standard-exclusive.

  • Deploy a VPN Gateway VpnGw5AZ to terminate all 140 site-to-site tunnels.

    Why it is wrong: VPN Gateway tops out at 100 S2S tunnels even on VpnGw4 and VpnGw5 SKUs; the documentation explicitly directs designers to Virtual WAN beyond 100 tunnels.

  • A VPN Gateway VpnGw4 with an active-active site-to-site connection over the public internet.

    Why it is wrong: VPN Gateway encrypts traffic but still traverses the public internet, so it does not meet the requirement for a path that never crosses the public internet.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.