AZ-305 Design infrastructure solutions Practice Question
A company is deploying an internal web application on Azure VMs. The application requires SSL offloading, session stickiness, and URL-based routing (e.g., /api/* to one backend, /app/* to another). The solution must operate within a single Azure region and must not be exposed to the public internet. Which Azure load balancing solution should they use?
⚠ Common exam trap
Many candidates confuse Azure Front Door with Application Gateway, but Front Door is a global service requiring public endpoints and multi-region support, whereas Application Gateway can be deployed privately within a single region.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
C
Azure Application Gateway v2 is the correct choice because it provides SSL offloading (SSL termination at the gateway), session stickiness (cookie-based affinity), and URL-based routing (path-based routing rules) within a single Azure region. It can be deployed with a private IP address only, ensuring it is not exposed to the public internet, meeting all requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A
Why it's wrong here
Azure Front Door is a global, edge-based Layer 7 load balancer that routes HTTP/S traffic across the internet using anycast and requires publicly resolvable endpoints. It cannot be deployed with a private VNet IP as its frontend; doing so would still expose the application to the public internet, which violates the internal-only deployment requirement. Its strength is multi-region and CDN scenarios, not a single-region internal workload.
- ✗
B
Why it's wrong here
Azure Traffic Manager is purely a DNS-based traffic router: it resolves a domain name to an endpoint IP but never inspects or forwards application traffic. Because it operates at the DNS layer, it cannot perform SSL offloading, cannot set cookie-based session affinity, and cannot make routing decisions on URL paths. Furthermore, the backend endpoints must have publicly accessible IP addresses or a public-facing endpoint, which contradicts the internal deployment model.
- ✓
C
Why this is correct
Azure Application Gateway can be deployed as an internal (private) application gateway with a private frontend IP address inside the VNet, keeping the application fully internal. It offers native Layer 7 features including SSL termination (offloading), cookie-based session affinity, and URL path-based routing through listener and rule configurations. This makes it the only option that satisfies all three requirements—SSL offloading, session stickiness, and URL-based routing—within an internal network boundary.
- ✗
D
Why it's wrong here
Azure Load Balancer is a Layer 4 (TCP/UDP) service that forwards traffic based on a five-tuple hash and never inspects application-layer payloads. It cannot route based on URL path segments, cannot offload SSL because it does not terminate TLS, and only provides source-IP-based distribution, not cookie-based or application-aware session affinity. Thus, it is unsuitable for a modern web application that needs advanced HTTP routing and offload.
Go deeper
Related to this question
Learn chapter
RPO and RTO Requirements for Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.