Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company deploys a web application on Azure VMs within a single region. They need to distribute incoming HTTP traffic across multiple VMs, offload SSL encryption, and maintain session persistence (sticky sessions) for user sessions. Which Azure load balancing solution should they use?

⚠ Common exam trap

Watch out — candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support SSL offloading and sticky sessions, but only Layer 7 solutions like Application Gateway or Front Door provide these application-layer features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Application Gateway

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that can route HTTP/HTTPS traffic, offload SSL/TLS encryption, and support session affinity (sticky sessions) using cookies. Unlike a Layer 4 load balancer, it can inspect application-layer data, making it ideal for web applications requiring SSL termination and persistent user sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Load Balancer

    Why it's wrong here

    Azure Load Balancer operates at Layer 4 of the OSI model, forwarding TCP/UDP traffic based on 5-tuple rules without inspecting HTTP payload. It cannot terminate TLS/SSL, so certificates remain on each VM, and its session persistence is limited to source IP affinity rather than HTTP cookie-based stickiness. This makes it unsuitable for an application that requires SSL offloading and cookie-based sticky sessions at the application layer.

  • ✓

    Azure Application Gateway

    Why this is correct

    Azure Application Gateway is a Layer 7 reverse proxy that understands HTTP/S, enabling SSL termination at the gateway so VMs receive decrypted traffic and offload cryptographic overhead. It provides cookie-based session affinity (sticky sessions) using Application Gateway Affinity cookies, ensuring requests from the same user session reach the same VM. These capabilities map directly to the deployment's requirement for inbound web traffic distribution within a single region, making it the correct choice.

  • ✗

    Azure Traffic Manager

    Why it's wrong here

    Azure Traffic Manager works at the DNS layer, directing clients to a service endpoint based on routing methods like performance or priority, but it does not intercept the actual HTTP traffic. Because it only returns a DNS response, it cannot inspect HTTP headers, offload SSL, or maintain session persistence; any TLS handshake and session logic must be handled by the destination service. It is also typically used across regions for global failover and traffic routing, not for distributing web traffic among VMs in a single region.

  • ✗

    Azure Front Door

    Why it's wrong here

    Azure Front Door is a global, anycast-based application delivery service that routes traffic through Microsoft's edge network to endpoints across regions, offering SSL offload and session affinity at a global scale. While it does support Layer 7 features, it is designed for accelerating and securing internet-facing global applications rather than for low-complexity distribution within a single region. Deploying it here would introduce unnecessary global routing and cost complexity, making Application Gateway the more appropriate single-region choice.

Go deeper

Related to this question

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.