A pharmaceutical company is developing an Azure AI solution to analyze medical images for disease detection. The solution involves training large deep learning models on highly sensitive patient data using Azure Machine Learning compute clusters. Due to regulatory mandates (e.g., HIPAA, GDPR), all compute resources must be isolated from the public internet and must not allow any inbound connections from external networks, even for management purposes. Which networking configuration within Azure Machine Learning would ensure this level of isolation for the compute cluster?
- AUtilizing Azure Firewall to restrict outbound internet access from the VNet.
- BPlacing the compute cluster in a dedicated subnet and allowing only outbound internet access.
- CDeploying the compute cluster into an Azure Virtual Network (VNet) with public IP addresses disabled and Azure Private Link enabled for the workspace.
- DConfiguring Network Security Groups (NSGs) to block all inbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploying the compute cluster into an Azure Virtual Network (VNet) with public IP addresses disabled and Azure Private Link enabled for the workspace.
Deploying the compute cluster into an Azure Virtual Network (VNet) with public IP addresses disabled ensures it has no public internet exposure. Additionally, enabling Azure Private Link for the Azure Machine Learning workspace ensures that all management and data plane traffic to the workspace (and thus to the compute cluster within the VNet) traverses a private endpoint, completely isolating it from the public internet, including inbound management connections.
Why the other options are wrong
- A. Azure Firewall restricts *outbound* internet access, which is important, but does not primarily address the *inbound* isolation requirement for the compute cluster and its management through the workspace.
- B. Placing in a dedicated subnet and allowing only outbound internet access helps with egress control, but it does not inherently prevent inbound public internet exposure for management traffic to the workspace unless Private Link is also implemented.
- D. While NSGs can block inbound traffic, they don't prevent the compute cluster from potentially having a public IP address or relying on public endpoints for management plane access to the workspace itself, which Private Link addresses.
Azure ML VNet Isolation with Private Link
Achieving complete network isolation for Azure Machine Learning compute resources by deploying them into a VNet with disabled public IPs and enabling Private Link for the workspace.
- Compute resources have no public IP addresses.
- All communication (data and management plane) travels over private endpoints.
- Prevents any inbound or outbound public internet exposure for the workspace and associated resources.
Memory trick: VNet Private Link 'Locks' ML compute from the world.