Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company deploys a containerized microservices application on Azure Kubernetes Service (AKS). They need to expose the application to the internet with TLS termination and provide a single endpoint for multiple services. The solution must also include a Web Application Firewall (WAF). Which Azure service should they use as the ingress controller?

⚠ Common exam trap

Many candidates confuse Azure Front Door (global, edge-based) with Application Gateway (regional, cluster-facing), assuming both can serve as an AKS ingress controller, but only Application Gateway integrates natively with AKS via AGIC for internal cluster routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Application Gateway with WAF

Azure Application Gateway with WAF is the correct choice because it is a regional, layer-7 load balancer that can act as an ingress controller for AKS. It provides TLS termination at the gateway and integrates a Web Application Firewall (WAF) to protect against common web exploits. This allows a single public endpoint to route traffic to multiple microservices within the AKS cluster based on URL paths or host headers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Application Gateway with WAF

    Why this is correct

    Azure Application Gateway with WAF is correct because the Application Gateway Ingress Controller (AGIC) runs inside AKS and watches Kubernetes Ingress resources, translating them into routing rules on the gateway. This allows TLS termination and WAF inspection at a single public endpoint, with L7 HTTP/S routing directly to the appropriate microservices. Unlike L4 or DNS-level services, it understands application paths, hostnames, and headers, making it a true ingress controller for AKS.

  • ✗

    Azure Front Door with WAF

    Why it's wrong here

    Azure Front Door provides global WAF, TLS termination, and a single endpoint, making it tempting for internet-facing applications. However, it operates as a global load balancer and CDN, not as an ingress controller that runs within an Azure Kubernetes Service (AKS) cluster. It cannot directly manage the internal HTTP/S routing rules to specific Kubernetes services based on ingress resources. Front Door would typically sit in front of an AKS cluster, requiring a separate ingress controller like Azure Application Gateway or NGINX within the cluster to handle the actual service routing.

  • ✗

    Azure Load Balancer with TLS termination

    Why it's wrong here

    Azure Load Balancer with TLS termination is incorrect because a standard Azure Load Balancer operates at Layer 4 (TCP/UDP) and forwards packets without inspecting HTTP messages. It cannot terminate TLS, as that requires decrypting HTTPS traffic at Layer 7, nor can it apply WAF rules or route requests based on URL paths or host headers. Its health probes merely check backend availability and are not a substitute for ingress-based routing to individual Kubernetes services.

  • ✗

    Azure Traffic Manager with health probes

    Why it's wrong here

    Azure Traffic Manager with health probes is incorrect because Traffic Manager works at the DNS level, not as an ingress controller for AKS. It resolves domain names to endpoints based on routing methods and health probes, but it cannot terminate TLS, inspect HTTP requests, or route to specific services or paths within a cluster. While it can distribute traffic across regions, it does not understand Kubernetes Ingress resources and therefore cannot replace Application Gateway or an NGINX-based ingress.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.