Topic Cram Sheet635 words

Cram Sheet — Design network solutions

AZ-305 › Unit 4 › Design network solutions

Cram Sheet — Design network solutions

Map communication flows to connectivity, routing, security, name resolution, load balancing, and observability controls. Use this sheet after the linked lessons: it is a retrieval map and decision aid, not a substitute for the worked examples.

Cram target

4
Design infrastructure solutions
4
Recommend and reject

Decision matrix

Requirement shapeStart withQualifying rule
Private hybrid connectivityExpressRoute or VPN GatewayChoose SLA, bandwidth, latency, encryption, and redundancy
Global HTTP entryAzure Front DoorEdge routing, acceleration, health probes, TLS, and WAF
Regional L7 entryApplication GatewayPrivate/public HTTP routing and WAF inside a region
Private PaaS accessPrivate Endpoint and Private DNSPlan DNS ownership, resolution paths, and public access policy

The phrase start with matters. A default is only defensible after checking all hard constraints: region and SKU support, protocols, scale, availability, security, residency, recovery, skills, and operating ownership. When two rows appear in one scenario, compose them rather than forcing one service to solve every concern.

Fast design method

  1. Name the workload boundary and the users or systems that cross it.
  2. Extract measurable requirements: latency, throughput, volume, RTO/RPO, consistency, outage window, and retention.
  3. Mark security and governance constraints: identity, network reachability, encryption, residency, audit, and separation of duties.
  4. Select the simplest viable default from the matrix.
  5. Test it against failure domains, scale transitions, deployment, monitoring, and cost.
  6. State the nearest alternative and the one constraint that makes it weaker.
Loading Diagram...
Figure 1 — Mermaid diagram

Text equivalent: derive requirements, choose a default, qualify it against constraints, add operational and failure behaviour, then explain the trade-off.

High-value traps

  • NSGs do not provide application-layer inspection.
  • Private Endpoint design is also a DNS design.
  • Peering is not transitive.

Scenario rehearsal

An organisation asks for the capability described by the first matrix row, but also adds a strict recovery target, private connectivity, and a small operations team. Write a recommendation that identifies the core service, the supporting continuity and network controls, and the operating trade-off. Then reject the nearest service alternative using one explicit requirement. If your answer lists products without a traffic, data, identity, or recovery flow, it is incomplete.

Final-minute checklist

  • I can distinguish every service in the matrix by requirement, not logo or name.
  • I know which controls operate at identity, management, data, and network planes.
  • I check regional/SKU support and current limits when a scenario depends on them.
  • I include monitoring, health, capacity, recovery, and ownership in the recommendation.
  • I can explain why the strongest distractor fails.
Loading flashcards…

Source and freshness

Aligned to the current AZ-305 study guide, the attached Exam Ref, and the attached AZ-305 study guide corpus. Current Microsoft Learn documentation controls product availability, limits, and renamed services. Reviewed 2026-08-02.

Ready to study Designing Microsoft Azure Infrastructure Solutions (AZ-305)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free