(Case study excerpt) Proseware requires that all connections routed via APPGW1 use end-to-end encryption and that the company use its internal CA whenever possible. APPGW1 currently routes traffic for App2 and must be configured to meet the end-to-end encryption requirement. Which of the following actions should you take to configure APPGW1 for end-to-end encryption and comply with the security requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Backend settings, upload a wildcard TLS certificate that has a private key issued by the internal root CA..
Why this is the answer
To achieve end-to-end encryption with Azure Application Gateway (APPGW1) and use an internal CA, you must upload the internal root CA certificate to the Backend settings. This allows the Application Gateway to trust the backend servers' certificates, which are issued by your internal CA. The correct option specifies uploading a wildcard TLS certificate with a private key issued by the internal root CA to the Backend settings. While a wildcard certificate can be used for backend servers, the critical part for end-to-end encryption with an internal CA is that the Application Gateway trusts the CA that issued the backend server certificates. Uploading a client certificate to SSL settings is for client authentication, not for the Application Gateway trusting backend servers. Uploading only the root CA certificate to Backend settings is correct, but the option about the wildcard certificate with a private key issued by the internal root CA is the most comprehensive and accurate description of what's needed for the backend server certificate itself, which the Application Gateway will then validate against the trusted root CA.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed