Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingEasy
A company is deploying a new web application on Azure and requires a highly available and scalable solution to distribute incoming HTTP/HTTPS traffic across multiple backend servers. The solution must also provide SSL offloading capabilities and integrate with Azure Web Application Firewall (WAF) for enhanced security. Which Azure networking service should be implemented?
- AAzure Load Balancer
- BAzure Application Gateway
- CAzure Traffic Manager
- DAzure Front Door
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Application Gateway
Azure Application Gateway is specifically designed for web traffic load balancing (HTTP/HTTPS), offering features like SSL offloading and native integration with Azure WAF, which aligns perfectly with the requirements.
Why the other options are wrong
- A. Azure Load Balancer operates at Layer 4 (TCP/UDP) and does not provide SSL offloading or WAF integration.
- C. Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic at the DNS level, not at the application layer, and lacks SSL offloading or WAF.
- D. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. While it offers Layer 7 features and WAF, the scenario describes a regional application deployment within Azure.
Azure Application Gateway
A web traffic load balancer that enables you to manage traffic to your web applications. It operates at Layer 7 (HTTP/HTTPS).
- Supports SSL/TLS termination (offloading)
- Includes Web Application Firewall (WAF) capabilities
- Can perform URL-based routing and session affinity
Memory trick: App Gateway for web, Load Balancer for general, Front Door for global, Traffic Manager for DNS.