Microsoft Azure Solutions Architect Expert AZ-305 Practice Question

Your company hosts several legacy ASP.NET applications on-premises that use Windows Integrated Authentication (Kerberos). Identities are synchronized to Azure Active Directory with Azure AD Connect. Management wants staff working from home to reach these applications over the internet without requiring a VPN. Access must be evaluated by Azure AD Conditional Access and the solution must avoid exposing the internal network or adding significant new infrastructure. Which approach should you recommend?

  • Deploy an Azure VPN Gateway and require users to establish a Point-to-Site VPN before accessing the applications.

  • Publish the applications by using Azure AD Application Proxy and configure Kerberos Constrained Delegation for single sign-on.

  • Deploy Azure AD Domain Services, join the web servers to the managed domain, and control access through Azure role assignments.

  • Migrate the applications to Azure App Service and enable Azure AD authentication with Conditional Access.

Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot