Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionHard

A financial institution is developing an Azure AI solution to analyze customer sentiment from online reviews. The solution will use Azure Cognitive Services for Text Analytics. Due to strict regulatory compliance requirements, all data processed by the AI services must reside within a specific geographic region and never leave it, even for management traffic. Which network security feature, in conjunction with Private Endpoints, provides the strongest guarantee that data remains within the Azure virtual network and specified region?

  1. AAzure Firewall
  2. BVNet Service Endpoints
  3. CNetwork Security Groups (NSGs)
  4. DAzure Front Door
Show answer & explanation

Correct answer: C. Network Security Groups (NSGs)

While Private Endpoints ensure data travels over the Microsoft backbone and into a VNet, NSGs provide granular control over network traffic within the VNet, explicitly allowing or denying connections to and from the Private Endpoint interface, thus enforcing regional data residency and preventing exfiltration.

Why the other options are wrong

  • A. Azure Firewall provides centralized network security but operates at a higher level than NSGs for specific VNet interface traffic control and isn't the primary mechanism for enforcing regional data residency for Private Endpoints.
  • B. VNet Service Endpoints extend VNet private address space to Azure services, but Private Endpoints offer more comprehensive private connectivity, and NSGs are still needed for granular traffic control within the VNet to enforce strict residency.
  • D. Azure Front Door is a global, scalable entry point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, but it's not designed for enforcing VNet-level data residency for backend AI services with Private Endpoints.

Network Security Groups (NSGs)

A security feature that filters network traffic to and from Azure resources in an Azure Virtual Network.

  • Acts as a virtual firewall for subnets and network interfaces.
  • Allows or denies traffic based on rules (source, destination, port, protocol).
  • Crucial for granular traffic control within a VNet, complementing Private Endpoints.

Memory trick: Private Endpoints are the 'private road,' NSGs are the 'guard rails' on that road.

More Plan and manage an Azure AI solution questions