Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company deploys a containerized application on Azure Kubernetes Service (AKS). They need to expose the application to the internet and provide TLS termination. The solution must also include a Web Application Firewall (WAF) to protect against common attacks. Which Azure service should they use as the ingress controller?

⚠ Common exam trap

It's easy for candidates to confuse Azure Front Door with Application Gateway because both provide WAF and TLS termination, but Front Door is a global service for multi-region traffic distribution, not a direct AKS ingress controller that can route to pods within a single cluster.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Application Gateway

Azure Application Gateway is the correct choice because it is a layer-7 load balancer that can act as an ingress controller for AKS, providing TLS termination and a built-in Web Application Firewall (WAF) to protect against common attacks like SQL injection and cross-site scripting. It integrates directly with AKS via the Application Gateway Ingress Controller (AGIC) add-on, allowing it to route external HTTP/HTTPS traffic to containerized applications while offloading SSL/TLS processing and enforcing WAF policies at the edge.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Application Gateway

    Why this is correct

    Azure Application Gateway, when integrated as the Application Gateway Ingress Controller (AGIC), is the native Azure L7 load balancer that serves as an ingress gateway for AKS clusters. It terminates TLS connections at the gateway, decrypts HTTP traffic, and enforces Web Application Firewall policies (such as OWASP CRS rules) before forwarding requests to AKS pods. This makes it the correct solution for the requirement of TLS termination and WAF in an AKS environment.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global, edge-based application delivery network that provides TLS termination, WAF, and HTTP/S acceleration, but it is not an AKS ingress controller and cannot be installed inside a cluster. Front Door routes traffic from the internet at the edge to a backend origin such as an Application Gateway, public IP, or AKS service, but it does not perform pod-level routing or integrate with AKS ingress resources. You would place Front Door in front of Application Gateway (or another origin) for global scaling, not as the ingress successor.

  • ✗

    Azure Load Balancer

    Why it's wrong here

    Azure Load Balancer is a Layer-4 (TCP/UDP) gateway that forwards IP packets to backend virtual machines or AKS nodes without inspecting the payload, so it cannot differentiate HTTP paths or hostnames. It does not support TLS termination because the connection is passed through unchanged, and it has no Web Application Firewall capability because it lacks HTTP-layer visibility. While an AKS service can use a Load Balancer to expose a workload, this option does not meet the TLS termination and WAF requirements.

  • ✗

    Azure Traffic Manager

    Why it's wrong here

    Azure Traffic Manager is a DNS-based traffic router that resolves client queries to regional endpoints but never proxies traffic between clients and your AKS workloads. Because it operates at the DNS layer only, it cannot see HTTP requests, terminate TLS, or apply Web Application Firewall rules, nor can it act as an AKS ingress controller. Traffic Manager simply points clients to the public IP of a service or another load balancer, making it unsuitable for HTTP-aware TLS termination or WAF.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.