Topic module

Application Gateway and Azure Front Door

This topic covers layer 7 routing, listeners, backend pools, HTTP settings, TLS, rewrites, Azure Front Door routing, caching, acceleration, and origin protection.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-700

Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.

Core concepts

Concept 1

Application Gateway and Azure Front Door questions test Azure networking design and troubleshooting choices rather than memorized portal paths.

Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.

Concept 2

The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.

Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.

Concept 3

Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.

Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.

Risk pitfalls and guardrails

Confusing DNS resolution with routing or security filtering.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.

Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.

Memory anchors

Application Gateway

Application Gateway provides layer 7 load balancing, path-based routing, TLS termination, and WAF integration.

Listener

A listener checks for incoming Application Gateway connection requests by frontend IP, port, protocol, and host.

Backend Pool

A backend pool contains the targets that receive application traffic.

HTTP Setting

HTTP settings define backend protocol, port, cookie affinity, timeout, and probe behavior.

Rewrite Rule

A rewrite rule can modify request or response headers and URLs.

Azure Front Door

Azure Front Door provides global HTTP routing, acceleration, TLS, caching, and WAF capabilities.

Origin

An origin is a backend service that Azure Front Door routes client requests to.

Front Door Rules Engine

Rules can modify routing, redirects, headers, caching, and request handling.

End to End TLS

End-to-end TLS encrypts traffic from client to edge and from edge to origin.

Origin Protection

Origin protection restricts direct access to backends and favors traffic through the delivery service.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An application needs host- and path-based routing for HTTP traffic inside one Azure region. Which service is the best fit?

An Application Gateway is deployed into a subnet shared with VMs. Why should the design be changed?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.