AZ-305 exam dumps

AZ-305 practice question 236 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 236

Single answer

Your company is migrating multiple line-of-business applications to Azure. Each application is hosted in its own spoke virtual network (VNet). The company wants to consolidate and centralize the management of inbound and outbound traffic, enable advanced threat detection, and easily scale security controls as new applications are added. Currently, only Network Security Groups (NSGs) are used per VNet, but the overhead of managing multiple rulesets for each application is becoming a challenge. Which recommendation should you make to optimize network security under these requirements?

  1. A

    Deploy Azure Firewall in a hub VNet and peer the spoke VNets, routing all traffic through Azure Firewall for centralized control.

  2. B

    Use a single NSG across all spokes and assign it to every subnet to simplify ruleset management.

  3. C

    Enable Azure DDoS Protection Standard on each VNet to automatically handle malicious traffic without additional configuration.

  4. D

    Implement an Azure Application Gateway with Web Application Firewall (WAF) in each spoke VNet for inbound and outbound security.

Show answer and explanation

Correct answer: A

Explanation

In a hub-and-spoke architecture, Azure Firewall is recommended for centralizing security policies and providing advanced threat protection for both inbound and outbound traffic. NSGs alone lack the layer 7 inspection and unified management features of Azure Firewall, and WAF primarily focuses on web traffic. Azure DDoS Protection Standard is important for mitigating volumetric attacks but does not replace a firewall solution. Refer to Azure Firewall best practices documentation for guidance on network design and rule configuration.

  • A. Correct.

    Option 1 is correct because Azure Firewall in a hub-and-spoke network architecture provides a centralized, scalable security solution that can inspect both inbound and outbound traffic. This approach allows you to manage security rules in a single place, offloads advanced threat detection from NSGs, and simplifies the network security deployment as new spokes are added.

  • B. Incorrect.

    Option 2 is incorrect because using a single NSG across all spokes does not provide advanced threat protection or centralized inspection. It also becomes complex to manage rules if multiple application requirements conflict, and NSGs alone do not offer the same feature set (e.g., threat intelligence) as Azure Firewall.

  • C. Incorrect.

    Option 3 is incorrect because Azure DDoS Protection focuses primarily on protecting against distributed denial-of-service attacks. It does not provide layer 7 inspection or fine-grained policy enforcement for routine inbound and outbound traffic. Relying on DDoS Protection alone is insufficient for comprehensive security.

  • D. Incorrect.

    Option 4 is incorrect because Azure Application Gateway with WAF is typically used for securing HTTP/HTTPS traffic at the application layer. While it helps with inbound traffic to web applications, it does not provide the broad outbound filtering or centralized inspection and logging capabilities that Azure Firewall does for all types of traffic.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam