AZ-305 Design infrastructure solutions Practice Question
A company deploys a web application on Azure VMs across multiple availability zones in a region. They need to distribute incoming traffic across VMs in all zones, maintain session persistence, and support SSL offloading and URL-based routing (e.g., /api/* to one pool, /app/* to another). Which Azure load balancing solution should they use?
⚠ Common exam trap
Watch out — candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support HTTP-level features like URL routing and SSL offloading, but only Layer 7 solutions do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway
Azure Application Gateway is the correct choice because it is a Layer 7 (HTTP/HTTPS) load balancer that supports SSL offloading, URL-based routing (e.g., /api/* and /app/* to different backend pools), and session persistence (cookie-based affinity). It can distribute traffic across VMs in multiple availability zones within a region, meeting all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Load Balancer
Why it's wrong here
Azure Load Balancer operates at the transport layer (L4) and makes forwarding decisions based on source/destination IP addresses, ports, and protocol—without inspecting HTTP request bodies or URLs. Consequently, it cannot perform URL-based path routing or terminate SSL sessions, which are critical for a web application that requires routing to different back-end pools based on the request path. While it is excellent for distributing TCP/UDP traffic and preserving a high-throughput, low-latency data path, it lacks the application-level awareness needed for this scenario.
- ✓
Azure Application Gateway
Why this is correct
Azure Application Gateway is a regional, layer-7 web traffic load balancer that understands HTTP(S) and offers native SSL termination (offloading), URL/path-based routing, multi-site hosting, cookie-based session affinity, and a built-in Web Application Firewall (WAF). This makes it the appropriate choice for a web application spread across multiple Azure VMs within the same region, because it can inspect each request's URL and steer it to the right backend pool. Its ability to offload encryption, rewrite HTTP headers, and perform health checks at the application layer matches the stated requirements precisely, and it is commonly deployed in front of VM scale sets for web workloads.
- ✗
Azure Traffic Manager
Why it's wrong here
Azure Traffic Manager is a DNS-based global traffic load balancer that operates entirely at the DNS query level, directing clients to the nearest or healthiest regional endpoint but having no visibility into the actual HTTP request path or URL. Because it only resolves endpoint IP addresses based on routing methods like priority, performance, or geographic location, it cannot inspect paths such as /images or /api to route within a single region and cannot perform SSL offloading. Its role is to distribute traffic across Azure regions for disaster recovery or geo-expansion, not to provide application-layer URL routing for VMs in a single Azure region.
- ✗
Azure Front Door
Why it's wrong here
Azure Front Door is a global, layer-7 load balancer and CDN that uses Microsoft's anycast network to route HTTP(S) traffic across regions to the nearest point of presence, making it designed for multi-region failover and acceleration rather than intra-region VM load balancing. While Front Door does support URL-based routing and SSL termination, its global scope and content-delivery features introduce additional latency and cost without benefit for a set of VMs colocated in a single Azure region. For a purely regional, single-region web application with URL-specific routing needs, Azure Application Gateway is the more aligned and cost-effective service.
Go deeper
Related to this question
Learn chapter
Multi-Region Active-Active Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.