nerdexam
MicrosoftMicrosoft

AZ-305 · Question #295

AZ-305 Question #295: Real Exam Question with Answer & Explanation

The correct answer is A: Azure Virtual WAN with a secured virtual hub. The Virtual WAN meets the first 3 requirements, and the secured virtual hub has the Azure Firewall Manager, which can do the FQDN filtering. https://learn.microsoft.com/en-us/azure/firewall-manager/secured-virtual-hub https://learn.microsoft.com/en-us/azure/firewall/fqdn-filterin

Submitted by haruto_sh· Mar 6, 2026

Question

Your company has offices in North America and Europe. You plan to migrate to Azure. You need to recommend a networking solution for the new Azure infrastructure. The solution must meet the following requirements: - The Point-to-Site (P2S) VPN connections of mobile users must connect automatically to the closest Azure region. - The offices in each region must connect to their local Azure region by using an ExpressRoute circuit. - Transitive routing between virtual networks and on-premises networks must be supported. - The network traffic between virtual networks must be filtered by using FQDNs. What should you include in the recommendation?

Options

  • AAzure Virtual WAN with a secured virtual hub
  • Bvirtual network peering and application security groups
  • Cvirtual network gateways and network security groups (NSGs)
  • DAzure Route Server and Azure Network Function Manager

Explanation

The Virtual WAN meets the first 3 requirements, and the secured virtual hub has the Azure Firewall Manager, which can do the FQDN filtering. https://learn.microsoft.com/en-us/azure/firewall-manager/secured-virtual-hub https://learn.microsoft.com/en-us/azure/firewall/fqdn-filtering-network-rules

Community Discussion

No community discussion yet for this question.

Full AZ-305 PracticeBrowse All AZ-305 Questions