Microsoft Azure Solutions Architect Expert AZ-305 Practice Question

Contoso runs multiple workloads in Azure using a hub-and-spoke virtual network topology. All Internet-bound traffic from the spoke VNets currently exits directly through the default system routes. The security team now requires central egress filtering, threat-intelligence-based blocking, and outbound TLS traffic inspection, together with built-in high availability and centralized policy management through Azure Firewall Manager. Which solution should you recommend to meet these requirements with minimal operational overhead?

  • Enable Azure DDoS Protection Standard on every spoke VNet and continue using the default system routes for outbound traffic.

  • Create network security groups with egress deny rules for known malicious IP ranges and associate them with all subnets in the spoke VNets.

  • Deploy a third-party network virtual appliance (NVA) firewall in every spoke VNet and route outbound traffic through the local appliance.

  • Deploy Azure Firewall Premium in the hub VNet as a secured virtual hub and configure user-defined routes from each spoke VNet to send all Internet traffic through the firewall.

Microsoft Azure Solutions Architect Expert AZ-305
Design infrastructure solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot