Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your company is designing a new cloud-native application on Azure that consists of multiple microservices running on Azure Kubernetes Service (AKS). The application must be accessible from the internet via a custom domain name (app.contoso.com) and must support SSL/TLS termination. You need to design a secure ingress solution that provides Web Application Firewall (WAF) capabilities, SSL offloading, and automatic scaling. The solution should also support path-based routing to different microservices (e.g., /api, /web). You have the following options: Option A: Deploy an Azure Application Gateway v2 with WAF in front of the AKS cluster. Configure Application Gateway Ingress Controller (AGIC) to route traffic to the services. Option B: Deploy an Azure Load Balancer with a public IP and install an NGINX ingress controller on AKS. Configure SSL termination on NGINX and use a third-party WAF. Option C: Deploy an Azure Front Door with WAF policy in front of the AKS cluster. Use Azure Private Link to connect Front Door to the internal load balancer of AKS. Option D: Deploy an Azure API Management instance with WAF and expose the microservices through API endpoints. Use Azure Application Gateway as a reverse proxy. Which option best meets the requirements for a high-performance, integrated, and managed solution with minimal operational overhead?

⚠ Common exam trap

Test-takers frequently confuse Azure Front Door's global load balancing capabilities with the need for a regional, AKS-integrated ingress controller that supports path-based routing and WAF, leading them to choose Option A despite its lack of native AKS ingress controller support.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy an Azure Application Gateway v2 with WAF in front of the AKS cluster. Configure Application Gateway Ingress Controller (AGIC) to route traffic to the services.

Azure Application Gateway v2 with WAF provides a fully managed, integrated ingress solution that natively supports SSL/TLS offloading, path-based routing, and Web Application Firewall capabilities. By using the Application Gateway Ingress Controller (AGIC), traffic is automatically routed to the appropriate AKS microservices based on URL paths (e.g., /api, /web), and the gateway can scale automatically based on load. This minimizes operational overhead while meeting all stated requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy an Azure Front Door with WAF policy in front of the AKS cluster. Use Azure Private Link to connect Front Door to the internal load balancer of AKS.

    Why it's wrong here

    Azure Front Door is a global, anycast-based load-balancing service designed to route traffic across multiple regions. For a single-region AKS deployment, sending traffic through Front Door's edge network adds an unnecessary network hop and introduces latency, while Private Link endpoints to the AKS internal load balancer incur extra cost and configuration complexity. Application Gateway v2, by contrast, is a regional L7 solution that keeps traffic within the region and integrates directly with AKS.

  • ✓

    Deploy an Azure Application Gateway v2 with WAF in front of the AKS cluster. Configure Application Gateway Ingress Controller (AGIC) to route traffic to the services.

    Why this is correct

    Application Gateway v2 is a regional, autoscaling, Layer 7 load balancer with a managed WAF that includes OWASP rule sets, making it a strong fit for exposing AKS-based microservices. By deploying AGIC, the Kubernetes Ingress resources are automatically translated into Application Gateway routing rules, so no separate ingress controller pod is required. It provides SSL termination, path-based routing, and zone redundancy, all while being fully managed by Azure, which reduces operational burden compared to self-managed ingress.

  • ✗

    Deploy an Azure Load Balancer with a public IP and install an NGINX ingress controller on AKS. Configure SSL termination on NGINX and use a third-party WAF.

    Why it's wrong here

    This approach delegates TLS termination, request routing, and web application firewall duties to an NGINX ingress controller and an external third-party WAF running on self-managed infrastructure. The Azure Load Balancer only provides Layer 4 transport rules and does not understand HTTP paths or host headers, so everything above L4 must be manually configured, scaled, and patched by your team. Compared to a managed L7 WAF ingress like Application Gateway, this significantly increases operational overhead and introduces more points of failure for security updates and routing rules.

  • ✗

    Deploy an Azure API Management instance with WAF and expose the microservices through API endpoints. Use Azure Application Gateway as a reverse proxy.

    Why it's wrong here

    Azure API Management is a full API gateway platform designed for publishing, versioning, securing, and monetizing APIs, which is unrelated to the stated requirement of simply exposing internal microservices behind a WAF. If you add it, you are also forced to route traffic through an extra Application Gateway reverse proxy, creating a multi-hop chain that adds latency and cost without business value. For this scenario, a single Application Gateway v2 configured with AGIC directly fronting the AKS services gives you the needed WAF protection and ingress control with far less complexity.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.