AZ-305 Design infrastructure solutions Practice Question
A company deploys a web application on multiple Azure VMs within an availability set. They need to distribute incoming HTTP traffic evenly across the VMs and provide health probe monitoring. The solution must support SSL termination and source IP affinity (session persistence). Which Azure load balancing solution should they choose?
⚠ Common exam trap
A common mix-up: candidates confuse Layer 4 load balancers (Azure Load Balancer) with Layer 7 application delivery controllers (Application Gateway), assuming that SSL termination and session persistence are available in all load balancing tiers, but these features require application-layer processing only provided by Application Gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway v2
Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that supports SSL termination, source IP affinity (session persistence), and health probe monitoring. It can distribute HTTP traffic evenly across VMs in an availability set while offloading SSL processing from the backend VMs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Load Balancer (Basic)
Why it's wrong here
Azure Load Balancer (Basic) is a layer-4 (transport) distributor that forwards TCP/UDP traffic without inspecting application payloads, so it cannot terminate SSL/TLS or make routing decisions based on HTTP headers or cookies. While it can provide basic source-IP session persistence, it lacks cookie-based affinity for web applications, has no SLA, and offers no health probe customization, making it inadequate for this scenario.
- ✗
Azure Load Balancer (Standard)
Why it's wrong here
Azure Load Balancer (Standard) also operates at layer-4, preserving encrypted traffic as opaque bytes and leaving SSL/TLS termination to the backend VMs. It improves on Basic with availability zones, richer health probes, and outbound SNAT, but its session persistence is still limited to source-IP hashing rather than application-layer cookies. Because it cannot decrypt HTTP traffic or inspect application headers, it fails to meet the SSL termination and cookie-based stickiness requirements.
- ✓
Azure Application Gateway v2
Why this is correct
Azure Application Gateway v2 is a regional layer-7 reverse proxy that terminates SSL/TLS at the gateway, offloading decryption from the backend VMs, and can optionally re-encrypt traffic to the origin pool. It provides cookie-based session affinity (ARRAffinity), configurable health probes, and URL/path-based routing, directly matching the need for SSL termination and persistent user sessions across multiple VMs. Its static VIPs and WebSocket support further solidify it as the correct L7 load-balancing choice in Azure.
- ✗
Azure Traffic Manager
Why it's wrong here
Azure Traffic Manager is a DNS-level traffic router that directs requests to global endpoints using methods like performance, priority, or weighted round-robin, but it never sits in the user-to-backend data path. It cannot see HTTP payloads, terminate SSL/TLS, or maintain local session affinity, because once DNS answers, the client connects directly to the endpoint. Its purpose is global failover and geographic distribution, not L7 load balancing among VMs within the same region or VNet, so it is unsuitable here.
Go deeper
Related to this question
Learn chapter
Designing Application Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.