AZ-305 exam dumps

AZ-305 practice question 224 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 224

Single answer

You are designing internet connectivity for a new line-of-business application running on several Azure Virtual Machines in a single subnet. The solution must provide a stable, dedicated public IP address for all outbound traffic while minimizing operational overhead. Which approach should you recommend?

  1. A

    Associate a unique public IP address with each VM’s network interface card (NIC).

  2. B

    Deploy an Azure NAT Gateway in the subnet where the VMs reside.

  3. C

    Enable a site-to-site VPN connection to route outbound internet traffic through the on-premises network.

  4. D

    Configure Virtual Network Service Endpoints for the Azure VMs.

Show answer and explanation

Correct answer: B

Explanation

Azure NAT Gateway is the recommended solution for providing internet connectivity with a stable, dedicated public IP address while minimizing operational overhead. This approach is particularly valuable when scaling out multiple instances in a subnet, as it centralizes NAT management. For more information, refer to Azure NAT Gateway best practices in the official documentation.

  • A. Incorrect.

    Option 1: While assigning a public IP to each virtual machine’s NIC does provide internet connectivity, managing multiple public IPs increases complexity and cost. It also doesn’t simplify NAT management, making it less optimal for large-scale deployments.

  • B. Correct.

    Option 2: Deploying an Azure NAT Gateway in the subnet is the most recommended solution. It automatically provides a dedicated public IP address for all outbound traffic, reduces overhead, and simplifies management by handling outbound connectivity at the subnet level.

  • C. Incorrect.

    Option 3: A site-to-site VPN is typically used for secure connectivity between an on-premises environment and Azure. It’s not designed to provide a stable, dedicated egress IP for internet-bound traffic from Azure VMs, making it an unsuitable choice for this requirement.

  • D. Incorrect.

    Option 4: Virtual Network Service Endpoints improve the security of traffic to specific Azure services by extending the virtual network private IP address space. This does not provide a dedicated public IP address for general internet egress traffic.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam