Microsoft Certified: Azure Developer Associate (AZ-204)Connect to and consume Azure services and third-party servicesMedium
A company is developing a new API using Azure Functions. They need to expose this API securely and reliably to external partners, apply transformation logic to requests and responses, and enforce usage quotas. Which Azure service should be used to achieve these requirements?
- AAzure Application Gateway
- BAzure API Management
- CAzure Front Door
- DAzure Load Balancer
Show answer & explanationAnswer & explanation
Correct answer: B. Azure API Management
Azure API Management (APIM) is specifically designed to provide a façade for APIs, offering features like security (authentication, authorization), request/response transformation, usage quotas (rate limiting, subscriptions), caching, and analytics, making it ideal for exposing backend APIs to external consumers. Front Door and Application Gateway are load balancers/WAFs, and Load Balancer is for network-level traffic distribution.
Why the other options are wrong
- A. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. It provides WAF capabilities but lacks the comprehensive API management features like policy-based transformations, subscriptions, and quotas.
- C. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It's a layer 7 load balancer and WAF, but not an API gateway for policy enforcement and transformation.
- D. Azure Load Balancer operates at layer 4 (TCP/UDP) and is used for distributing network traffic across backend instances. It does not provide API-specific security, transformation, or quota enforcement.
Azure API Management (APIM)
Azure API Management is a hybrid, multi-cloud management platform for APIs across all environments. It helps organizations publish, secure, transform, maintain, and monitor APIs.
- Provides a unified façade for APIs.
- Offers security, transformation, and policy enforcement.
- Enables usage quotas and rate limiting.
- Supports developer portal, analytics, and caching.
Memory trick: APIM is the doorman, security, and manager for your API party.