Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A global e-commerce company uses Azure to host its customer-facing web application. They need to ensure that only traffic from their corporate network and specific trusted partner networks can access the application's backend APIs hosted on Azure App Service. Additionally, they must prevent direct public internet access to these backend APIs. Which Azure networking and security features should be combined to achieve this?

  1. AAzure DDoS Protection Standard with Traffic Manager
  2. BAzure Virtual Network (VNet) Integration with Network Security Groups (NSGs)
  3. CAzure Front Door with Web Application Firewall (WAF)
  4. DAzure Private Link with Service Endpoints
Show answer & explanation

Correct answer: B. Azure Virtual Network (VNet) Integration with Network Security Groups (NSGs)

VNet Integration allows the App Service to reside within a virtual network, preventing direct public internet access. NSGs can then be applied to the VNet subnet to filter inbound traffic based on source IP ranges (corporate and partner networks), effectively restricting access to the backend APIs.

Why the other options are wrong

  • A. DDoS Protection protects against denial-of-service attacks, and Traffic Manager distributes traffic across endpoints. Neither directly addresses restricting access to specific IP ranges or preventing public internet access to an App Service backend.
  • C. Front Door and WAF protect against web attacks and route traffic, but don't inherently restrict backend access to specific VNet IP ranges or prevent direct public access to an App Service backend.
  • D. Private Link provides private connectivity to Azure services, and Service Endpoints provide secure access to Azure services from a VNet. While related to private access, VNet Integration with NSGs specifically addresses the scenario of restricting an App Service's inbound access to specific VNet sources and blocking public access comprehensively.

VNet Integration + NSG

Azure Virtual Network (VNet) Integration for App Service allows an app to access resources in or through a VNet, effectively placing the app within a private network. Network Security Groups (NSGs) then filter network traffic to and from resources in an Azure VNet.

  • VNet Integration prevents public internet access to App Service
  • NSGs enable granular IP-based traffic filtering
  • Used together for private and controlled access to backend services
  • Can secure inbound and outbound traffic

Memory trick: VNet Integration is the House, NSG is the Door Guard.

More Design identity, governance, and monitoring solutions questions