Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsHard
An educational institution is hosting a research portal on Azure. They need to ensure that only authenticated users from the institution's network can access the portal, and all data transmitted between users and the portal is encrypted. They also need to ensure that the portal's backend web servers are not directly exposed to the public internet. Which combination of Azure services should be used to meet these requirements?
- AAzure Application Gateway, Azure AD, and Private Endpoints
- BAzure App Service, Azure AD, and a Web Application Firewall (WAF)
- CAzure Virtual Network (VNet), Azure AD, and a VPN Gateway
- DAzure Front Door, Azure AD, and Network Security Groups (NSGs)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Virtual Network (VNet), Azure AD, and a VPN Gateway
A Virtual Network (VNet) provides network isolation for the portal's backend servers, preventing direct public internet exposure. A VPN Gateway allows secure, encrypted access from the institution's network to the VNet. Azure AD provides the authentication for users. This combination addresses all requirements.
Why the other options are wrong
- A. Application Gateway manages traffic to web applications but still primarily deals with public exposure. Private Endpoints are for private *inbound* access to PaaS services, not typically for routing user traffic through a VPN to IaaS/PaaS backend in this specific scenario. Azure AD is correct for authentication.
- B. App Service hosts the web app, and WAF protects against web attacks, but neither inherently ensures the backend is not directly exposed to the public internet while allowing VPN access from a specific network. Azure AD is correct for authentication.
- D. Front Door is a global load balancer for public-facing web applications. NSGs can filter, but Front Door still exposes the application publicly. Azure AD is correct for authentication.
VNet + VPN Gateway + Azure AD
Azure Virtual Network (VNet) provides private network isolation. A VPN Gateway creates a secure, encrypted connection to a VNet from on-premises networks. Azure Active Directory (Azure AD) provides centralized user authentication for applications.
- VNet isolates resources from public internet
- VPN Gateway enables secure, encrypted on-premises connectivity
- Azure AD provides robust user authentication
- Combined, they ensure private, authenticated, encrypted access
Memory trick: VNet is the House, VPN is the Private Road, AD is the Key.