Bird
Raised Fist0
Azurecloud~20 mins

Application Gateway (Layer 7) in Azure - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Azure Application Gateway Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ service_behavior
intermediate
2:00remaining
How does Azure Application Gateway handle HTTP requests with path-based routing?

Consider an Azure Application Gateway configured with path-based routing rules. What happens when a client sends an HTTP request to a URL path that matches one of the defined routing rules?

AThe Application Gateway forwards the request to the backend pool associated with the matching path rule.
BThe Application Gateway rejects the request with a 403 Forbidden error.
CThe Application Gateway forwards the request to all backend pools simultaneously.
DThe Application Gateway redirects the request to the frontend IP address.
Attempts:
2 left
💡 Hint

Think about how path-based routing directs traffic to specific backend pools.

❓ security
intermediate
2:00remaining
What happens if you enable Web Application Firewall (WAF) on Azure Application Gateway and a request contains a SQL injection attack?

Azure Application Gateway has Web Application Firewall (WAF) enabled. A client sends a request containing a SQL injection attack pattern. What is the expected behavior?

AThe Application Gateway forwards the request to the backend pool without inspection.
BThe Application Gateway redirects the request to a custom error page hosted on the backend.
CThe Application Gateway logs the attack but allows the request to pass through.
DThe WAF detects the attack and blocks the request before it reaches the backend pool.
Attempts:
2 left
💡 Hint

Consider the purpose of WAF in protecting web applications.

❓ Architecture
advanced
2:00remaining
Which Azure Application Gateway configuration supports SSL termination and end-to-end SSL encryption simultaneously?

You want to configure Azure Application Gateway to decrypt incoming SSL traffic and then re-encrypt it before sending to backend servers. Which configuration achieves this?

AConfigure the Application Gateway to use TCP load balancing.
BEnable SSL passthrough on the Application Gateway without SSL certificates.
CEnable SSL termination on the Application Gateway and configure HTTPS listeners and backend HTTPS settings with certificates.
DDisable SSL termination and use HTTP listeners only.
Attempts:
2 left
💡 Hint

Think about how SSL termination and re-encryption work together.

✅ Best Practice
advanced
2:00remaining
What is the recommended way to scale Azure Application Gateway to handle increased traffic?

Your web application is experiencing increased traffic. How should you scale Azure Application Gateway to maintain performance?

AIncrease the instance count of the Application Gateway and enable autoscaling.
BManually increase the size of backend VMs only.
CAdd more backend pools without changing the Application Gateway.
DSwitch to a Basic SKU Application Gateway for better performance.
Attempts:
2 left
💡 Hint

Consider how Application Gateway scales to handle more requests.

🧠 Conceptual
expert
2:00remaining
What is the effect of enabling the 'Cookie-based affinity' feature on Azure Application Gateway?

Azure Application Gateway supports 'Cookie-based affinity'. What does enabling this feature do?

AIt caches cookies at the Application Gateway to reduce backend load.
BIt ensures that all requests from a client session are routed to the same backend server by using a cookie.
CIt encrypts cookies to enhance security between client and backend.
DIt disables session persistence and distributes requests randomly.
Attempts:
2 left
💡 Hint

Think about how session persistence works in load balancing.

Practice

(1/5)
1. What is the main function of an Azure Application Gateway at Layer 7?
easy
A. It stores data in a scalable database.
B. It manages virtual machines in a subnet.
C. It routes web traffic based on URL paths and content.
D. It provides DNS resolution for domain names.

Solution

  1. Step 1: Understand Layer 7 role

    Layer 7 means the application layer, which handles web traffic content like URLs.
  2. Step 2: Identify Application Gateway function

    Application Gateway routes traffic based on URL paths and content, unlike DNS or VM management.
  3. Final Answer:

    It routes web traffic based on URL paths and content. -> Option C
  4. Quick Check:

    Layer 7 routing = URL-based traffic routing [OK]
Hint: Layer 7 means web content routing, not VM or DNS tasks [OK]
Common Mistakes:
  • Confusing Application Gateway with DNS or VM services
  • Thinking it works at network layer instead of application layer
  • Assuming it stores data like a database
2. Which of the following is the correct way to define a frontend IP configuration for an Azure Application Gateway in ARM template JSON?
easy
A. {\"name\": \"appGatewayFrontendIP\", \"properties\": {\"publicIPAddress\": {\"id\": \"/subscriptions/.../publicIPAddresses/myPublicIP\"}}}
B. {\"name\": \"appGatewayFrontendIP\", \"location\": \"eastus\"}
C. {\"frontendIP\": \"myPublicIP\"}
D. {\"ipConfig\": {\"publicIP\": \"myPublicIP\"}}

Solution

  1. Step 1: Review ARM template frontend IP syntax

    The frontend IP config requires a name and properties including a reference to a public IP resource by its ID.
  2. Step 2: Match correct JSON structure

    {\"name\": \"appGatewayFrontendIP\", \"properties\": {\"publicIPAddress\": {\"id\": \"/subscriptions/.../publicIPAddresses/myPublicIP\"}}} correctly uses "name" and "properties" with "publicIPAddress" and its "id" field, matching ARM schema.
  3. Final Answer:

    {"name": "appGatewayFrontendIP", "properties": {"publicIPAddress": {"id": "/subscriptions/.../publicIPAddresses/myPublicIP"}}} -> Option A
  4. Quick Check:

    Frontend IP config needs name + publicIPAddress id [OK]
Hint: Look for 'properties' with 'publicIPAddress' and 'id' fields [OK]
Common Mistakes:
  • Missing 'properties' wrapper around publicIPAddress
  • Using 'location' inside frontend IP config incorrectly
  • Incorrect field names like 'frontendIP' or 'ipConfig'
3. Given this simplified ARM snippet for an Application Gateway backend HTTP settings, what will be the effect of setting "pickHostNameFromBackendAddress" to true?
{
  "name": "appGatewayBackendHttpSettings",
  "properties": {
    "port": 80,
    "protocol": "Http",
    "pickHostNameFromBackendAddress": true
  }
}
medium
A. The backend hostname is taken from the backend pool IP or FQDN instead of the HTTP settings.
B. The Application Gateway ignores the backend pool and uses the frontend hostname.
C. The backend HTTP settings port is ignored and defaults to 443.
D. The Application Gateway disables SSL termination.

Solution

  1. Step 1: Understand 'pickHostNameFromBackendAddress'

    This setting tells the gateway to use the hostname from the backend pool's address (IP or FQDN) for HTTP requests.
  2. Step 2: Analyze effect on backend requests

    When true, the hostname in HTTP headers matches backend pool address, not the HTTP settings hostname.
  3. Final Answer:

    The backend hostname is taken from the backend pool IP or FQDN instead of the HTTP settings. -> Option A
  4. Quick Check:

    pickHostNameFromBackendAddress true = use backend pool hostname [OK]
Hint: True means use backend pool hostname, not HTTP settings hostname [OK]
Common Mistakes:
  • Thinking it changes port or protocol
  • Confusing frontend hostname with backend hostname
  • Assuming it disables SSL termination
4. You deployed an Application Gateway but it fails to route traffic to backend servers. The backend pool uses IP addresses, but the health probes always fail. What is a likely cause?
medium
A. The Application Gateway subnet is too large.
B. The backend HTTP settings have 'pickHostNameFromBackendAddress' set to true but backend IPs lack proper DNS names.
C. The frontend IP configuration is missing a public IP address.
D. The backend pool uses FQDNs instead of IP addresses.

Solution

  1. Step 1: Understand health probe failure with IP backend pool

    If 'pickHostNameFromBackendAddress' is true, the gateway uses backend hostname from IP, which fails if no DNS name exists.
  2. Step 2: Identify mismatch causing probe failure

    Backend IPs lack DNS names, so probes fail when hostname is required but missing.
  3. Final Answer:

    The backend HTTP settings have 'pickHostNameFromBackendAddress' set to true but backend IPs lack proper DNS names. -> Option B
  4. Quick Check:

    IP backend + pickHostNameFromBackendAddress true = probe fails [OK]
Hint: Check if backend IPs have DNS names when pickHostNameFromBackendAddress is true [OK]
Common Mistakes:
  • Blaming subnet size for routing issues
  • Assuming frontend IP config missing public IP causes backend probe failure
  • Confusing backend pool IPs with FQDNs
5. You want to configure an Azure Application Gateway to route requests to different backend pools based on URL paths: /images/* to an image server pool and /api/* to an API server pool. Which configuration step is essential to achieve this?
hard
A. Configure the backend HTTP settings to use HTTPS only.
B. Assign multiple public IP addresses to the frontend configuration.
C. Use multiple frontend ports with the same backend pool.
D. Create path-based routing rules with URL path maps specifying backend pools for each path.

Solution

  1. Step 1: Understand URL-based routing requirement

    Routing based on URL paths requires path-based routing rules with URL path maps.
  2. Step 2: Configure path-based rules

    Define URL path maps that link specific URL patterns like '/images/*' and '/api/*' to their respective backend pools.
  3. Final Answer:

    Create path-based routing rules with URL path maps specifying backend pools for each path. -> Option D
  4. Quick Check:

    URL path routing = path-based rules with URL maps [OK]
Hint: Use path-based routing rules with URL maps for URL path routing [OK]
Common Mistakes:
  • Thinking multiple public IPs are needed for URL routing
  • Using multiple frontend ports without path rules
  • Assuming backend HTTP settings control URL routing