AZ-305 Design infrastructure solutions Practice Question
A company is deploying a multi-tier web application on Azure. The web tier must be accessible from the internet. The application tier and database tier must be isolated within the virtual network and not directly accessible from the internet. The solution must provide SSL termination, URL-based routing, and Web Application Firewall (WAF) capabilities. Which Azure service should they use to expose the web tier?
⚠ Common exam trap
Many candidates confuse Azure Front Door with Application Gateway because both offer layer-7 features, but Front Door is a global load balancer that does not provide VNet-level isolation for backends, whereas Application Gateway is regionally scoped and integrates directly with virtual networks for internal tier isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway
Azure Application Gateway is a layer-7 load balancer that provides SSL termination, URL-based routing, and a built-in Web Application Firewall (WAF). It can expose the web tier to the internet while keeping the application and database tiers isolated within the virtual network, as it routes traffic to backend pools using HTTP/HTTPS rules without exposing those backends directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Application Gateway
Why this is correct
Azure Application Gateway is the correct choice because it operates at Layer 7, enabling SSL termination, URL path-based routing, and integrated WAF to filter malicious traffic. It can be deployed in a dedicated subnet within the same VNet as the web and database tiers, allowing it to forward requests to a backend pool via private IP addresses while the database tier remains isolated behind NSGs. This combination of HTTP-level routing, security, and VNet integration satisfies the multi-tier isolation requirement.
- ✗
Azure Load Balancer
Why it's wrong here
Azure Load Balancer operates at Layer 4, forwarding traffic based on TCP/UDP source and destination IPs and ports without inspecting HTTP content. As a result, it cannot perform SSL termination, route based on URL paths, or offer a web application firewall, so it leaves critical web-tier protections unimplemented. Even when it is placed entirely inside the VNet, it lacks the application-layer intelligence needed to direct requests toward different backend services, making it an inadequate stand-in for a modern web tier load balancer.
- ✗
Azure Traffic Manager
Why it's wrong here
Azure Traffic Manager resolves DNS queries to select a public endpoint from among globally distributed endpoints, making it a DNS-level routing service rather than a network load balancer. It does not terminate TLS, inspect HTTP headers, or route requests to private VMs in a single region, so it cannot enforce application-layer rules or contribute to isolating the web tier. For a multi-tier application hosted in one region, it introduces unnecessary global complexity without providing any layer-7 functionality and would not replace the security and routing capabilities of Application Gateway.
- ✗
Azure Front Door
Why it's wrong here
While Azure Front Door offers SSL termination, URL-based routing, and WAF, it does not inherently provide the necessary network isolation for the application and database tiers. It's tempting because it excels at global traffic management and security for web applications, making it ideal for scenarios requiring a single global entry point with advanced routing and protection, but it doesn't fulfil the requirement of isolating backend tiers within a private virtual network.
Go deeper
Related to this question
Learn chapter
Designing Application Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.