Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
An Azure Kubernetes Service (AKS) cluster has 40 nodes in two private subnets of a hub-and-spoke virtual network. Pods open tens of thousands of concurrent TCP sessions to partner SaaS endpoints that will whitelist only one public IPv4 address. Corporate policy blocks unsolicited inbound traffic to the node subnets. You must design egress so that:
All outbound traffic uses a single static public IP
SNAT ports scale automatically to avoid exhaustion
No pod changes or operational overhead are required
Which Azure service meets the requirements?
Create a Standard Public Load Balancer for the cluster nodes and configure an outbound rule that uses a static front-end IP.
Deploy an Azure Application Gateway with Web Application Firewall and route all egress traffic through it.
Attach an Azure NAT Gateway to the two AKS node subnets and assign it a single static public IP address.
Assign instance-level public IP addresses to every AKS node and restrict inbound NSG rules to outbound-only traffic.
Azure NAT Gateway attaches to one or more subnets and translates all outbound traffic to a designated static public IP address or prefix. Each public IPv4 address supplies up to 64,512 SNAT ports, and the service can automatically add more addresses from an assigned prefix as needed, preventing port exhaustion. NAT Gateway does not accept unsolicited inbound connections, satisfying the security policy and removing the need to configure load-balancer rules or individual node IPs. Standard Load Balancer outbound SNAT, instance-level public IPs, and Application Gateway either risk port exhaustion, violate the single-IP requirement, or are intended for inbound traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure NAT Gateway?
Open an interactive chat with Bash
How does NAT Gateway prevent SNAT port exhaustion?
Open an interactive chat with Bash
Why is NAT Gateway preferred over a Standard Load Balancer for this scenario?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design infrastructure solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .