You have a private AKS cluster AKS1 connected to VNet1, and VNet1 is connected to your on-premises network via ExpressRoute. You need an off-cluster ingress controller for AKS1 that provides connectivity from the on-premises environment to containerized workloads in AKS1. Which Azure service should host the off-cluster ingress?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Application Gateway.
Why this is the answer
Azure Application Gateway is the correct choice because it's a Layer 7 (HTTP/S) load balancer that can be deployed within a VNet, making it accessible from your on-premises network via ExpressRoute. It supports advanced routing features like URL-based routing and SSL termination, essential for an ingress controller. Azure Front Door is incorrect because it's a global, CDN-like service that operates at the edge of Microsoft's network, not within your VNet, and doesn't integrate directly with private AKS clusters for internal ingress. Azure Traffic Manager is a DNS-based traffic routing service, not an ingress controller, and doesn't handle application-layer routing. Azure Load Balancer operates at Layer 4 (TCP/UDP) and lacks the advanced HTTP/S routing capabilities required for an ingress controller.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed