AZ-305 Design infrastructure solutions Practice Question
Your organization is migrating an on-premises application to Azure. The application consists of a load-balanced web tier and a backend SQL Server database. The web tier requires session persistence (sticky sessions) and SSL offload. You need to design a solution that meets these requirements with minimal operational overhead. Which Azure service should you use for the web tier load balancing?
⚠ Common exam trap
It's easy for candidates to confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support SSL offload and sticky sessions, but only Layer 7 services can inspect HTTP traffic for these features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Application Gateway
Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that natively supports HTTP-based session persistence (sticky sessions) via cookie affinity and SSL termination (offload) at the gateway. This meets both requirements while minimizing operational overhead, as it handles SSL certificates and session affinity without requiring changes to the web tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Traffic Manager
Why it's wrong here
Azure Traffic Manager is a DNS-level load balancer that routes incoming DNS queries to per-region endpoints based on routing methods such as performance, priority, or geographic. Since it resolves only at the DNS layer, it cannot inspect HTTP requests, terminate TLS/SSL certificates, or maintain cookie-based session affinity, so it fails to provide sticky sessions or SSL offload. Additionally, for a single-region migration, its global failover focus adds irrelevant complexity rather than addressing the stated application-layer requirements.
- ✓
Azure Application Gateway
Why this is correct
Azure Application Gateway is a regional, Layer 7 reverse proxy explicitly built for HTTP/HTTPS workloads, making it the correct choice for an on-premises migration that needs session affinity and SSL termination. Its cookie-based session affinity preserves client sessions to the same backend server, and its SSL offload capability decrypts HTTPS traffic at the gateway so backend VMs avoid CPU-intensive encryption work. These features map directly to the requirements, and the gateway operates within a single region, aligning with the migration scale.
- ✗
Azure Front Door
Why it's wrong here
Azure Front Door is a global Layer 7 service that does support cookie-based session affinity and SSL offload, but it is engineered for multi-region active-active delivery, internet acceleration via anycast, and global failover. For a single-region application being lifted to Azure, all of that global routing logic is unnecessary, introduces disproportionate cost and configuration overhead, and adds a Microsoft edge network dependency that provides no application-layer value in this scenario. A regional service like Application Gateway delivers the needed features with less complexity.
- ✗
Azure Load Balancer
Why it's wrong here
Azure Load Balancer is a Layer 4 service that operates at the transport level, distributing TCP/UDP traffic by 5-tuple hash without examining the HTTP payload. Because it never inspects HTTP headers or cookies, it cannot perform SSL offload, and its built-in session persistence is limited to source IP or IP+protocol rather than application-aware cookie-based affinity. For an HTTPS application requiring TLS termination and sticky HTTP sessions, a Layer 4 load balancer fundamentally lacks the protocol awareness needed.
Go deeper
Related to this question
Learn chapter
Designing Application Architecture
Key term
Application Gateway Design
Application Gateway Design is the process of planning and configuring a layer 7 load balancer in Azure that routes web traffic based on URL paths, hostnames, or other HTTP rules for secure, scalable, and high-performance application delivery.
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.