Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionEasy

A company is developing an Azure AI solution that will process sensitive customer data. The solution will use Azure Cognitive Services. You need to ensure that all data processed by the Cognitive Services instance remains within the company's virtual network and is not exposed to the public internet. Which networking configuration should you implement?

  1. AConfigure an Azure Private Endpoint for the Cognitive Services instance.
  2. BUse Azure Application Gateway with VNet integration.
  3. CImplement Azure Front Door with Web Application Firewall (WAF) rules.
  4. DConfigure a Service Endpoint for the Cognitive Services instance.
Show answer & explanation

Correct answer: A. Configure an Azure Private Endpoint for the Cognitive Services instance.

Azure Private Endpoint provides a private IP address for a service within a virtual network, ensuring that traffic to the service traverses the Azure backbone network privately and is not exposed to the public internet.

Why the other options are wrong

  • B. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. While it can be integrated with a VNet, it primarily focuses on routing and security at the application layer, not private connectivity to Azure services themselves.
  • C. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, but it doesn't privatize access to backend services within a VNet.
  • D. Service Endpoints allow VNet traffic to reach Azure services over an optimized route but still use public IP addresses for the service, which doesn't meet the requirement of no public internet exposure.

Azure Private Endpoint

A network interface that connects you privately and securely to a service powered by Azure Private Link. Private Endpoint uses a private IP address from your VNet, effectively bringing the service into your VNet.

  • Provides private connectivity to Azure services.
  • Traffic traverses the Azure backbone network.
  • Ensures data is not exposed to the public internet.

Memory trick: Private Endpoints keep your AI's secrets truly private within your VNet.

More Plan and manage an Azure AI solution questions