Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company has 15 spoke virtual networks peered to a central hub in Azure. Each spoke hosts workloads that must access the internet and on-premises networks. The security team requires a single service in the hub that inspects inbound and outbound traffic up to layer 7, blocks malicious IPs using Microsoft threat-intelligence feeds, and automatically scales while remaining available during an availability-zone failure. Which design should you implement?
Associate Network Security Groups with every subnet in the spokes and enable adaptive network hardening to block malicious IPs.
Enable Azure DDoS Protection Standard on the hub virtual network to mitigate attacks and rely on default system routes for traffic inspection.
Provision a regional Application Gateway with Web Application Firewall in the hub and configure the gateway IP as the next hop for all spoke traffic.
Deploy Azure Firewall Premium in the hub virtual network, enable zone-redundant deployment, and add user-defined routes in each spoke to send all traffic through the firewall.
Azure Firewall Premium delivers centralized, stateful inspection for both ingress and egress traffic across layers 3-7, integrates Microsoft threat-intelligence filtering to block known malicious IP addresses, automatically scales to meet throughput demand, and supports zone-redundant deployments for high availability. Placing the firewall in the hub and forcing all spoke traffic through it with user-defined routes meets every stated requirement.
DDoS Protection Standard only mitigates large-scale denial-of-service attacks and does not inspect regular inbound or outbound traffic. Network Security Groups provide layer 3/4 filtering per subnet or NIC and lack threat-intelligence feeds or central management. Application Gateway with Web Application Firewall secures only inbound HTTP/HTTPS traffic and therefore cannot inspect outbound or non-HTTP flows, nor is it intended as a full network firewall.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Firewall Premium, and why is it suitable for this scenario?
Open an interactive chat with Bash
What are user-defined routes (UDRs) in Azure, and how are they configured in this design?
Open an interactive chat with Bash
What is zone redundancy in Azure, and how does it improve firewall availability?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design infrastructure solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .