For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAzure Solutions Architect Expert (AZ-305)Azure Solutions Architect Expert AZ-305 Practice Exam 3Question 52
    Medium1 markMultiple Choice
    Domain 4.4: Design network solutionsDomain 4Network SolutionsAzure FirewallCase Study
    This question is part of a case study — click to read the full scenario(Case 51)

    CASE STUDY (Questions 51-55)

    Contoso Financial is a global investment bank.

    Current Infrastructure:

    • On-premises datacenters in New York, London, and Tokyo.
    • Azure regions used: US East, Europe West, Japan East.
    • Each on-premises datacenter is connected to its local Azure region via a 10 Gbps ExpressRoute circuit.
    • Azure architecture uses a Hub-and-Spoke topology in each region.

    Business Requirements:

    • The network architecture must support global failover. If the US East region fails, the New York datacenter must be able to route traffic to the Europe West Azure region.
    • All outbound internet traffic from Azure VMs must be inspected by a centralized firewall.
    • Azure PaaS services (SQL, Storage) must not be accessible from the public internet.
    • Network management overhead must be minimized as the company plans to add 50 more spoke VNets per region next year.

    Question 1 of 5:
    To meet the global failover requirement, the New York datacenter must be able to communicate with the Europe West Azure region if US East fails.

    Which ExpressRoute feature or architecture should you implement?

    View full case study page →

    AZ-305 · Question 52 · Domain 4.4: Design network solutions

    CASE STUDY (Questions 51-55)

    Contoso Financial is a global investment bank.

    Current Infrastructure:

    • On-premises datacenters in New York, London, and Tokyo.
    • Azure regions used: US East, Europe West, Japan East.
    • Each on-premises datacenter is connected to its local Azure region via a 10 Gbps ExpressRoute circuit.
    • Azure architecture uses a Hub-and-Spoke topology in each region.

    Business Requirements:

    • The network architecture must support global failover. If the US East region fails, the New York datacenter must be able to route traffic to the Europe West Azure region.
    • All outbound internet traffic from Azure VMs must be inspected by a centralized firewall.
    • Azure PaaS services (SQL, Storage) must not be accessible from the public internet.
    • Network management overhead must be minimized as the company plans to add 50 more spoke VNets per region next year.

    Question 2 of 5:
    To meet the requirement for centralized outbound internet inspection, you deploy Azure Firewall in the Hub VNet.

    The security team mandates that the firewall must be able to inspect the payload of encrypted HTTPS traffic to detect malware, and it must use signature-based detection to block known malicious traffic.

    Which TWO features of Azure Firewall must you utilize? (Select TWO)

    Answer options:

    A.

    TLS Inspection

    B.

    Network Rules

    C.

    Intrusion Detection and Prevention System (IDPS)

    D.

    Threat Intelligence based filtering

    E.

    Application Rules

    How to approach this question

    Identify the features required for 'payload of encrypted HTTPS' (TLS Inspection) and 'signature-based detection' (IDPS). Both require Azure Firewall Premium.

    Full Answer

    To inspect the payload of encrypted HTTPS traffic, Azure Firewall Premium must be used with 'TLS Inspection' enabled. This allows the firewall to act as a man-in-the-middle to decrypt and inspect the traffic. To use signature-based detection for malware, the 'Intrusion Detection and Prevention System (IDPS)' feature must be enabled. Both features are exclusive to the Premium SKU of Azure Firewall.

    Common mistakes

    Confusing Threat Intelligence (IP/Domain blocking) with IDPS (deep packet signature inspection).
    Question 51All questionsQuestion 53

    Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 3

    55 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01Contoso Ltd is a global manufacturing company with 50,000 employees across 30 countries. They cur...MediumQ02Fabrikam Inc. is a Managed Service Provider (MSP) managing Azure environments for 50 different en...HardQ03A financial institution generates 5 TB of telemetry and audit logs daily across its Azure environ...MediumQ04A retail company has recently migrated several workloads to Azure. The IT Director wants a centra...EasyQ05A healthcare organization with 10,000 employees uses on-premises Active Directory. They are migra...Hard
    View all 55 questions →