Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionMedium

An e-commerce company is developing an Azure AI solution to provide a smart chatbot using Azure Bot Service and Azure Cognitive Services Language Understanding (LUIS). The chatbot needs to integrate with existing on-premises customer relationship management (CRM) systems and product databases for real-time information retrieval. The company has strict security policies that prohibit opening inbound ports to their on-premises network from the public internet. Which Azure networking solution should be used to enable secure and private communication between the Azure AI solution and the on-premises resources?

  1. AAzure VPN Gateway
  2. BAzure Public IP addresses
  3. CAzure DNS Private Zones
  4. DAzure Virtual Network peering
Show answer & explanation

Correct answer: A. Azure VPN Gateway

Azure VPN Gateway allows you to establish secure, encrypted connections between your Azure virtual networks and your on-premises networks over the public internet (Site-to-Site VPN) or from individual client machines (Point-to-Site VPN). This enables private communication without exposing on-premises systems to inbound public internet requests, meeting the security requirements.

Why the other options are wrong

  • B. Azure Public IP addresses expose resources to the public internet, directly violating the company's security policy.
  • C. Azure DNS Private Zones provide name resolution within a virtual network and connected networks, but do not establish the underlying secure network connectivity.
  • D. Azure Virtual Network peering connects two Azure VNets, but does not extend connectivity to on-premises networks directly.

Azure VPN Gateway (Site-to-Site)

Azure VPN Gateway enables secure, encrypted, and private connectivity between Azure Virtual Networks and on-premises networks over the public internet.

  • Creates an IPsec/IKE VPN tunnel.
  • Allows resources in Azure and on-premises to communicate privately.
  • Does not require opening inbound public ports to on-premises for Azure services.

Memory trick: VPN 'Gate' guards the path to on-prem.

More Plan and manage an Azure AI solution questions