Hard1 markMultiple Choice
Domain 4.4: Network SolutionsDomain 4ExpressRouteHybrid ConnectivityNetworking
This question is part of a case study — click to read the full scenario(Case 51)

CASE STUDY: Contoso Manufacturing

Overview: Contoso Ltd is a global manufacturing company with 50,000 employees across 30 countries. They currently operate a mix of on-premises infrastructure (500 VMware VMs across 5 data centers) and Azure (20 subscriptions with 100+ VMs and various PaaS services). Their annual IT budget is $50 million, with plans to migrate 70% of workloads to Azure within 2 years.

Business Requirements: The company needs to reduce IT costs by 30%, improve disaster recovery (current RTO: 24 hours -> target: 2 hours), enhance security posture to meet ISO 27001 and SOC 2 compliance, and enable remote work for 80% of employees. All solutions must support future growth of 20% annually.

Technical Constraints: Some legacy applications cannot be modified and must run on Windows Server 2012 R2. Network connectivity requires 10 Gbps throughput to Azure with <20ms latency. GDPR compliance mandates that EU customer data must remain in European Azure regions.

Question:
To meet the security and compliance requirements, Contoso wants to ensure that all outbound internet traffic from their Azure Virtual Networks is inspected and filtered centrally.

Which network architecture should you implement?

AZ-305 · Question 55 · Domain 4.4: Network Solutions

CASE STUDY: Contoso Manufacturing

Overview: Contoso Ltd is a global manufacturing company with 50,000 employees across 30 countries. They currently operate a mix of on-premises infrastructure (500 VMware VMs across 5 data centers) and Azure (20 subscriptions with 100+ VMs and various PaaS services). Their annual IT budget is $50 million, with plans to migrate 70% of workloads to Azure within 2 years.

Business Requirements: The company needs to reduce IT costs by 30%, improve disaster recovery (current RTO: 24 hours -> target: 2 hours), enhance security posture to meet ISO 27001 and SOC 2 compliance, and enable remote work for 80% of employees. All solutions must support future growth of 20% annually.

Technical Constraints: Some legacy applications cannot be modified and must run on Windows Server 2012 R2. Network connectivity requires 10 Gbps throughput to Azure with <20ms latency. GDPR compliance mandates that EU customer data must remain in European Azure regions.

Question:
To meet the 10 Gbps throughput and <20ms latency requirement for the hybrid connection between the on-premises data centers and Azure, which connectivity solution MUST Contoso implement?

Answer options:

A.

Site-to-Site VPN Gateway (VpnGw5)

B.

Azure ExpressRoute with a 10 Gbps circuit

C.

Azure Front Door

D.

Azure Peering Service

How to approach this question

Identify the hybrid networking service that provides dedicated, high-bandwidth, low-latency connections.

Full Answer

B.Azure ExpressRoute with a 10 Gbps circuit✓ Correct
Azure ExpressRoute Direct
Azure ExpressRoute provides a private, dedicated connection to Azure. Because it bypasses the public internet, it can guarantee low latency (<20ms) and high throughput (up to 10 Gbps for standard circuits, or 100 Gbps for ExpressRoute Direct). A Site-to-Site VPN traverses the public internet, so latency is unpredictable and cannot be guaranteed.

Common mistakes

Choosing VPN Gateway. While high-end VPN gateways can technically reach 10 Gbps, they cannot guarantee the strict <20ms latency requirement because they rely on the public internet.

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 2

55 questions · hints · full answers · grading

More questions from this exam