Memory hook: Choose the traffic layer, then preserve origin access, TLS and inspection symmetry.
Must remember
- Load Balancer handles Layer 4 flows; Application Gateway handles regional HTTP/S routing; Front Door handles global HTTP/S delivery. Configure backend pools/origin groups, probes, rules and failover priorities according to the selected product.
- Host/path routing needs correct host headers and backend TLS/SNI. Front Door origins should reject unwanted bypass paths using supported origin-access controls. Caching requires deliberate keys, TTL and invalidation; never cache personalised responses as shared public content.
- WAF managed/custom/rate-limit rules inspect web requests; choose detection/prevention and exclusions based on observed false positives. Azure Firewall supports network/application rules and SKU-specific capabilities; policy hierarchy and rule processing order matter. NSGs filter connections at subnet/NIC scopes.
- DDoS protection addresses volumetric/network attacks under the selected plan; it does not replace WAF or secure application logic. Network Manager can centrally manage supported connectivity/security configurations; staged rollout avoids widespread incorrect routing.
- Private Link service exposes supported provider services through consumer private endpoints. Approvals, endpoint subresources, DNS and backend configuration all matter. Service endpoints are a different mechanism and still use service public endpoints with network identity/rules.
- Centralised inspection must handle symmetric stateful flows and zone failures. TLS inspection requires a supported SKU/configuration, certificate trust and a reasoned exception policy. Do not assume encrypting traffic means a firewall can inspect its application payload.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Block malicious HTTP payload patterns | WAF on a supported application delivery service. |
| Inspect outbound destination domains | Appropriate Firewall application rules and DNS design. |
| Expose a specific service privately to consumers | Private Link service/endpoints where supported. |
Traps
- TLS termination and end-to-end TLS are different designs.
- A health probe can succeed while the requested host/path fails.
- A firewall can be bypassed by an unintended alternate route.
Active recall
1. Which layer is Application Gateway primarily designed for?
HTTP/S application-layer routing.
2. Why restrict direct origin access behind Front Door?
Otherwise clients can bypass intended edge controls.
3. What should WAF exclusions be based on?
A narrow understood false positive, tested against the security requirement.
4. Why does inspection need symmetry?
Stateful devices must observe a coherent connection flow.
5. What remains necessary after private endpoint approval?
Correct DNS, routing, service configuration and data authorisation.