Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsEasy

A company is designing a highly available network architecture for its mission-critical application deployed across multiple virtual machines within a single Azure region. The application requires internal load balancing for backend VMs and must be resilient to individual VM failures. Which Azure service should be used to distribute traffic to the backend virtual machines?

  1. AAzure Traffic Manager
  2. BAzure Front Door
  3. CAzure Application Gateway
  4. DAzure Load Balancer
Show answer & explanation

Correct answer: D. Azure Load Balancer

Azure Load Balancer is a Layer 4 (TCP/UDP) load balancer that distributes incoming traffic among healthy virtual machines within a single Azure region. It provides high availability and resilience to individual VM failures, making it ideal for internal load balancing of mission-critical applications.

Why the other options are wrong

  • A. Azure Traffic Manager is a DNS-based global load balancer for distributing traffic across multiple regions, not for internal load balancing within a single region.
  • B. Azure Front Door is a global Layer 7 load balancer for multi-region deployments, not for internal load balancing within a single region.
  • C. Azure Application Gateway is a Layer 7 (HTTP/HTTPS) load balancer and WAF, suitable for web applications, but not strictly required for internal non-HTTP traffic.

Azure Load Balancer

A Layer 4 (TCP/UDP) load balancer that distributes incoming traffic to healthy virtual machines or services within a single Azure region.

  • Operates at Layer 4 (TCP/UDP).
  • Supports both internal (private) and external (public) load balancing.
  • Provides high availability and fault tolerance.
  • Regional service, not global.

Memory trick: Load Balancer 'balances' traffic inside one 'region'.

More Design infrastructure solutions questions