AZ-305 Design infrastructure solutions Practice Question
A company deploys a containerized application on Azure Kubernetes Service (AKS). They need to expose the application to the internet and provide TLS termination. The solution must also include a Web Application Firewall (WAF) to protect against common attacks. Which Azure service should they use as the ingress controller?
⚠ Common exam trap
It's easy for candidates to confuse Azure Front Door with Application Gateway because both provide WAF and TLS termination, but Front Door is a global service for multi-region traffic distribution, not a direct AKS ingress controller that can route to pods within a single cluster.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway
Azure Application Gateway is the correct choice because it is a layer-7 load balancer that can act as an ingress controller for AKS, providing TLS termination and a built-in Web Application Firewall (WAF) to protect against common attacks like SQL injection and cross-site scripting. It integrates directly with AKS via the Application Gateway Ingress Controller (AGIC) add-on, allowing it to route external HTTP/HTTPS traffic to containerized applications while offloading SSL/TLS processing and enforcing WAF policies at the edge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Application Gateway
Why this is correct
Azure Application Gateway, when integrated as the Application Gateway Ingress Controller (AGIC), is the native Azure L7 load balancer that serves as an ingress gateway for AKS clusters. It terminates TLS connections at the gateway, decrypts HTTP traffic, and enforces Web Application Firewall policies (such as OWASP CRS rules) before forwarding requests to AKS pods. This makes it the correct solution for the requirement of TLS termination and WAF in an AKS environment.
- ✗
Azure Front Door
Why it's wrong here
Azure Front Door is a global, edge-based application delivery network that provides TLS termination, WAF, and HTTP/S acceleration, but it is not an AKS ingress controller and cannot be installed inside a cluster. Front Door routes traffic from the internet at the edge to a backend origin such as an Application Gateway, public IP, or AKS service, but it does not perform pod-level routing or integrate with AKS ingress resources. You would place Front Door in front of Application Gateway (or another origin) for global scaling, not as the ingress successor.
- ✗
Azure Load Balancer
Why it's wrong here
Azure Load Balancer is a Layer-4 (TCP/UDP) gateway that forwards IP packets to backend virtual machines or AKS nodes without inspecting the payload, so it cannot differentiate HTTP paths or hostnames. It does not support TLS termination because the connection is passed through unchanged, and it has no Web Application Firewall capability because it lacks HTTP-layer visibility. While an AKS service can use a Load Balancer to expose a workload, this option does not meet the TLS termination and WAF requirements.
- ✗
Azure Traffic Manager
Why it's wrong here
Azure Traffic Manager is a DNS-based traffic router that resolves client queries to regional endpoints but never proxies traffic between clients and your AKS workloads. Because it operates at the DNS layer only, it cannot see HTTP requests, terminate TLS, or apply Web Application Firewall rules, nor can it act as an AKS ingress controller. Traffic Manager simply points clients to the public IP of a service or another load balancer, making it unsuitable for HTTP-aware TLS termination or WAF.
Go deeper
Related to this question
Learn chapter
Hybrid Connectivity: VPN Gateway vs ExpressRoute
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.