Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium
A company is deploying a new web application on Azure. The application has a public-facing frontend and an internal API backend. Both are hosted on Azure Virtual Machines (VMs) within the same virtual network. The frontend VMs need to communicate with the API backend VMs. The API backend VMs must not be directly accessible from the internet. You need to implement a solution that distributes traffic to the API backend VMs and ensures they are not internet-facing. Which Azure networking component should you use for the API backend?
- AInternal Standard Load Balancer
- BPublic Standard Load Balancer
- CAzure Front Door
- DAzure Application Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. Internal Standard Load Balancer
An Internal Standard Load Balancer is designed to distribute traffic to VMs within a virtual network. It uses a private IP address and does not expose the backend VMs to the internet, perfectly meeting the requirement for distributing traffic to internal API backend VMs while keeping them private.
Why the other options are wrong
- B. A Public Standard Load Balancer exposes backend VMs to the internet, which contradicts the requirement that the API backend VMs must not be directly accessible from the internet.
- C. Azure Front Door is a global, public-facing service primarily for web applications across regions. It is not suitable for internal-only API backends within a single VNet.
- D. Azure Application Gateway is a Layer 7 (HTTP/HTTPS) load balancer. While it can be internal, the question specifies general API backend traffic, and an internal Load Balancer is more fundamental and suitable for Layer 4 distribution without the overhead of an Application Gateway if Layer 7 features are not strictly required.
Internal Azure Load Balancer
An Azure Load Balancer that uses a private IP address for its frontend, distributing traffic only to resources within a virtual network or connected on-premises networks.
- Operates at Layer 4 (TCP/UDP).
- Provides high availability for internal services.
- Not accessible from the public internet.
Memory trick: Internal LB: Your private traffic cop, only for insiders.