AZ-305 Design infrastructure solutions Practice Question
A company plans to deploy a multi-tier application on Azure. The web tier requires SSL termination and health probes. The application tier must be isolated from the internet. The database tier requires high availability. They want to minimize administrative overhead and use Azure native services. Which architecture should they recommend?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Front Door or Traffic Manager with Application Gateway for SSL termination and health probes, or assume that geo-restore provides the same automatic high availability as active geo-replication, leading them to choose options that either lack required features or increase administrative overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway for web tier, Azure Load Balancer (internal) for application tier, and Azure SQL Database with active geo-replication
Azure Application Gateway provides SSL termination and health probes for the web tier, an internal Azure Load Balancer isolates the application tier from the internet, and Azure SQL Database with active geo-replication offers high availability with automatic failover, minimizing administrative overhead by using PaaS services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Application Gateway for web tier, Azure Load Balancer (internal) for application tier, and Azure SQL Database with active geo-replication
Why this is correct
Azure Application Gateway is the correct ingress for the web tier because it performs L7 functions such as SSL termination, cookie affinity, and WAF rules while routing HTTP traffic to backend web apps. An internal Standard Load Balancer then distributes L4 network traffic among application-tier VMs, keeping that tier private from the internet. Azure SQL Database with active geo-replication maintains a readable secondary in a different Azure region, which supports a low-RPO manual or managed failover for business continuity. Together these services align with a typical multi-tier architecture and provide both high availability and regional resiliency.
- ✗
Azure Front Door for web tier, Azure Load Balancer for database tier, and SQL Server on Azure VMs with Always On
Why it's wrong here
Azure Front Door is a global reverse proxy with HTTP/HTTPS and WebSocket support; it is unnecessary for a single-region app because its main benefits like global anycast and cross-region load balancing do not apply. Placing an Azure Load Balancer in the database tier is a conceptual mismatch because Load Balancer operates at L4 (TCP/UDP) and cannot understand SQL Server semantics such as query routing or read/write split. Running SQL Server on Azure VMs with Always On adds the overhead of patching, OS management, and availability group configuration, unlike the PaaS SQL Database which provides built-in replication. This combination incorrectly addresses both networking layer and data-tier availability.
- ✗
Azure Traffic Manager for web tier, Azure Application Gateway for database tier, and Azure SQL Database with failover groups
Why it's wrong here
Azure Traffic Manager works at the DNS level to route traffic by geographically resolved endpoints; it cannot terminate SSL, inspect HTTP headers, or provide application-layer health probing, so it is a poor fit for a web tier that needs HTTPS offload. Using Azure Application Gateway in the database tier is fundamentally wrong because it is designed to route HTTP/S traffic and does not act as a database load balancer for SQL connections. Azure SQL Database failover groups themselves are a strong data-tier HA mechanism, but the overall option pairs them with inappropriate network components and thus is not the right architecture.
- ✗
Azure Application Gateway for web tier, Azure Load Balancer (internal) for application tier, and Azure SQL Database with geo-restore
Why it's wrong here
The web- and app-tier choices here are appropriate: Application Gateway for SSL termination and an internal Load Balancer for private application traffic. However, SQL Database geo-restore is a backward point-in-time restore capability that creates a database from a geo-redundant backup, not a high-availability replica; it is designed for disaster recovery with hours of downtime, not automatic failover. Active geo-replication, by contrast, maintains a continuous readable secondary and allows a controlled failover, making geo-restore the wrong HA mechanism for a multi-tier production application.
Go deeper
Related to this question
Learn chapter
Azure NAT Gateway for Outbound Connectivity
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.