Microsoft Azure Solutions Architect Expert AZ-305 Practice Question

Your company hosts an on-premises ASP.NET Core web API that must be consumed by several external partner organizations. The partners already authenticate with their own Azure AD tenants. You must expose the API while meeting the following requirements:

  • Authenticate and authorize users by using Azure AD groups.
  • Enforce Azure AD Conditional Access policies for multifactor authentication.
  • Avoid opening any inbound ports through the corporate firewall or adding new perimeter-network infrastructure.

You need to recommend the simplest Azure-based approach.

Which solution should you recommend?

  • Install an Azure AD Application Proxy connector on the on-premises network and publish the API through Azure AD Application Proxy.

  • Deploy Azure AD Domain Services in Azure, join the API server to the managed domain, and enable Azure AD Kerberos authentication.

  • Establish a site-to-site VPN to Azure and publish the API behind an internal Load Balancer fronted by Azure Application Gateway.

  • Set up Active Directory Federation Services (AD FS) with Web Application Proxy in a perimeter network and federate the partner Azure AD tenants.

Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot