GregLab | Exam Prep

Design infrastructure solutions

Connectivity, Performance, Security, and Traffic Routing

Core

Design internet, hybrid, east-west, and global connectivity with the appropriate routing, security, performance, and application-delivery controls.

Aligned to the current AZ-305 study guide, skills measured as of April 17, 2026, verified August 25, 2026.

Why this matters

Network architecture must preserve reachability, segmentation, inspection, name resolution, and performance across failure and trust boundaries.

Must Know

  • Choose VPN Gateway, ExpressRoute, or Virtual WAN according to internet encryption, private provider connectivity, or large-scale transit needs.
  • Match Load Balancer, Application Gateway, Front Door, and Traffic Manager to the required protocol layer and geographic scope.
  • Apply network security groups, Azure Firewall, and Private Link at their respective traffic-filtering, centralized-inspection, and private-service-access boundaries.
  • Design addressing, routes, DNS, ingress, egress, inspection, and failure behavior as one connectivity system.

Compare and Distinguish

  • VPN Gateway provides encrypted connectivity over the internet; ExpressRoute provides private connectivity through a provider; Virtual WAN integrates large-scale branch and transit connectivity.
  • Azure Load Balancer handles regional Layer 4 traffic; Application Gateway handles regional HTTP(S) delivery and WAF; Front Door provides global HTTP(S) entry, acceleration, and routing; Traffic Manager uses DNS.
  • Network security groups filter subnet or interface traffic; Azure Firewall provides centralized network and application rules; Private Link privately exposes supported services.

Scenario examples

  • Scenario: A bank requires private predictable connectivity backed by a service-provider circuit. Think: ExpressRoute with resilient circuit and gateway design.
  • Scenario: A global web app needs edge acceleration, WAF, and regional failover. Think: Front Door in front of regional origins.
  • Scenario: PaaS access must stay on private IP space. Think: Private Link with private DNS integration.

Exam traps

  • VNet peering is not transitive by default.
  • A private endpoint does not automatically configure every DNS resolver.
  • An NSG is not a centralized outbound filtering and logging substitute for Azure Firewall.

Key takeaways

  • Start with flows, trust zones, failure scope, and latency.
  • Match each control to layer and geographic scope.
  • Validate routing and DNS together because either can break connectivity.
How it works
  • Azure combines system routes, propagated gateway routes, and user-defined routes into each network interface's effective routes; the selected next hop determines whether traffic stays direct, traverses an appliance, or exits through a gateway.
  • Network security groups evaluate stateful allow and deny rules at subnet or interface boundaries, while a routed Azure Firewall path applies centralized network and application policy to traffic that actually reaches it.
  • Front Door proxies HTTP(S) traffic at the global edge, regional load balancers or application gateways distribute traffic to probed backends, and Traffic Manager returns DNS answers rather than carrying the application traffic.
Objects and administrative surfaces
  • Address space, route propagation, transitivity, DNS, egress, ingress, DDoS protection, inspection, and overlapping networks must be designed explicitly.
  • Hub-spoke, Virtual WAN, and direct peering models trade central control, scale, and operations complexity.
  • Global routing and regional load balancing often compose rather than compete.
When to use it
  • Use VPN Gateway for encrypted internet connectivity and ExpressRoute for private provider connectivity with predictable hybrid requirements.
  • Use Front Door for global HTTP(S), Application Gateway for regional Layer 7, and Load Balancer for regional Layer 4 traffic.
  • Use Private Link for private service access and Azure Firewall when routed traffic needs centralized filtering and logging.
Security and governance implications
  • Force only intended flows through inspection, restrict route and firewall changes, and keep application encryption even on private circuits where required.
  • Design DDoS protection, WAF, NSGs, Firewall, and Private Link at their proper layers instead of expecting one control to cover all traffic.
How to validate and revise the design
  • For failed connectivity, inspect name resolution, effective routes, next hops, gateway state, peering, NSG rules, firewall logs, and endpoint approval.
  • For poor performance or failover, compare path latency, circuit or gateway capacity, health probes, backend status, caching, and route convergence.
More detail
  • ExpressRoute keeps connectivity off the public internet, but a private circuit does not remove application-encryption requirements; VPN can also be used as a separate resilience path when the design calls for it.
  • Virtual network peering is not transitive, and overlapping address spaces prevent straightforward peering, so hub routing or Virtual WAN must be designed explicitly rather than inferred from connected spokes.
  • Private Link assigns a private endpoint address for a supported service, but clients must resolve the service name to that address and public network access remains a separate configuration decision.

Ready for the quiz?

  • Is the flow regional or global, private or internet-based, Layer 4 or HTTP(S), and where must inspection occur?
  • Which route, DNS answer, security rule, private endpoint, or gateway determines the actual packet path?
  • Does the hybrid design require encrypted internet transport, private provider connectivity, or large-scale managed transit?

Related objectives

  • D4.4.S1 — Recommend a connectivity solution that connects Azure resources to the internet
  • D4.4.S2 — Recommend a connectivity solution that connects Azure resources to on-premises networks
  • D4.4.S3 — Recommend a solution to optimize network performance
  • D4.4.S4 — Recommend a solution to optimize network security
  • D4.4.S5 — Recommend a load-balancing and routing solution

Learn more

Free Microsoft Certified: Azure Solutions Architect Expert prep

Build focused AZ-305 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

AZ-305 at a glance

Level
Expert
Duration
No fixed live duration published
Questions
No fixed live question count published
Formats
No guaranteed question-type mix
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for AZ-305. This lane contains multiple-choice exam-style practice; no supplemental matching, ordering, or case-study exercises were needed. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Expert-level architecture and trade-off complexity rather than a Microsoft-published question rating.

Reference

AZ-305 topics and reference map

Study links

AZ-305 resources