You have an Azure Application Gateway that load-balances traffic to a web app named App1 and you require end-to-end encryption (TLS) from client to backend. You configured an HTTPS listener by uploading an enterprise-signed certificate to the listener. What additional step is required so the Application Gateway can terminate and then establish TLS to the App1 backend (end-to-end encryption)?
Choose an answer
Tap an option to check your answer.
Correct answer: Upload the public key certificate to the HTTP settings..
Why this is the answer
To achieve end-to-end TLS encryption with Azure Application Gateway, you must upload the public key certificate of the backend server to the Application Gateway's HTTP settings. This allows the Application Gateway to validate the backend server's identity and encrypt traffic to it. The Application Gateway uses the certificate uploaded to the listener to decrypt client traffic, and the certificate in the HTTP settings to re-encrypt traffic to the backend. Increasing the unhealthy threshold for the probe is unrelated to TLS encryption. Enabling an SSL profile on the listener is not a standard Application Gateway setting for this purpose. Setting the listener type to Multi-site is for routing traffic to different backend pools based on host headers, not for enabling end-to-end TLS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed