โ† All AZ-305 Flashcard Decks

Azure Networking Architecture Design Flashcards

6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Azure Networking Architecture Design flashcards as text
  1. Your company wants to enforce that no virtual network in any subscription can have a peering connection to an unauthorized VNet. Which Azure service enforces this?

    Answer: Azure Policy with deny effects

    Azure Policy with a deny effect can audit and prevent VNet peering creation that does not meet your organizational naming or network space requirements.

  2. You need to route traffic from Azure to on-premises through a network virtual appliance (NVA) in the hub VNet. What must the NVA have enabled to forward traffic between interfaces?

    Answer: IP Forwarding

    IP Forwarding must be enabled on the NVA's NIC so Azure does not drop packets destined for other IP addresses.

  3. A workload spans two Azure regions and needs fast, low-latency failover routing for TCP/UDP traffic. Which Azure service provides this?

    Answer: Azure Cross-Region Load Balancer

    Azure Cross-Region Load Balancer provides Layer 4 global load balancing across regions with ultra-low latency failover for non-HTTP workloads.

  4. You need to segment a subnet so that VMs within the same subnet cannot communicate with each other unless explicitly allowed. Which feature enables intra-subnet traffic control?

    Answer: Application Security Groups with NSG rules

    Application Security Groups logically group VMs and NSG rules can reference them to allow or deny traffic between groups within the same subnet.

  5. Which Azure Firewall feature allows it to perform deep packet inspection and decrypt TLS traffic to detect and block hidden threats?

    Answer: Azure Firewall Premium with TLS inspection and IDPS

    Azure Firewall Premium includes TLS inspection (MITM decryption) and IDPS (Intrusion Detection and Prevention System) for deep packet analysis.

  6. You need to design a network that segments Azure resources into isolated tiers (web, app, data) with controlled traffic flow between tiers. What is the foundational design pattern?

    Answer: Use separate subnets with NSGs and UDRs between each tier

    Separate subnets per tier with NSGs controlling allowed ports and UDRs optionally routing through an NVA is the standard n-tier Azure network design.