Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingEasy

A company is deploying a critical application in Azure across multiple virtual machines (VMs) within a single virtual network. To ensure high availability and distribute incoming traffic efficiently among these VMs, a Layer 4 load balancer is required. The load balancer must support both internal and internet-facing endpoints. Which Azure networking service should be used?

  1. AAzure Front Door
  2. BAzure Traffic Manager
  3. CAzure Application Gateway
  4. DAzure Load Balancer
Show answer & explanation

Correct answer: D. Azure Load Balancer

Azure Load Balancer operates at Layer 4 (TCP/UDP) and can be configured as either a public (internet-facing) or internal (private IP) load balancer, meeting the requirements for distributing traffic to VMs within a VNet.

Why the other options are wrong

  • A. Azure Front Door is a global Layer 7 load balancer and CDN, not designed for regional Layer 4 load balancing within a VNet.
  • B. Azure Traffic Manager is a DNS-based traffic distribution service, not a Layer 4 load balancer.
  • C. Azure Application Gateway is a Layer 7 (HTTP/HTTPS) load balancer, not Layer 4.

Azure Load Balancer

A Layer 4 (TCP/UDP) load balancer that distributes incoming network traffic across multiple backend resources or instances.

  • Operates at the transport layer (Layer 4).
  • Can be public (internet-facing) or internal (private IP).
  • Supports health probes to monitor backend instance availability.

Memory trick: Layer 4 = Load Balancer, Layer 7 = Application Gateway.

More Implement and manage virtual networking questions