Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A healthcare provider is deploying a new patient portal application to Azure App Service. The application needs to securely access a PostgreSQL database hosted in an Azure Virtual Network (VNet) that is not exposed to the public internet. The security architect must ensure that all traffic between the App Service and the PostgreSQL database remains entirely within the Azure backbone network and does not traverse the public internet, while also simplifying network configuration. Which networking feature should the architect recommend?

  1. AVNet Peering
  2. BService Endpoints
  3. CAzure Private Link
  4. DVPN Gateway
Show answer & explanation

Correct answer: C. Azure Private Link

Azure Private Link enables private connectivity from Azure App Service (or other Azure services) to Azure PaaS services (like Azure Database for PostgreSQL) over a private endpoint in your VNet. This ensures that traffic remains entirely within the Azure backbone network, never traversing the public internet, and simplifies network configuration compared to other methods.

Why the other options are wrong

  • A. VNet Peering connects two Azure Virtual Networks, allowing resources in one VNet to communicate with resources in another. This is for VNet-to-VNet communication, not for connecting an Azure App Service directly to a private PaaS database within a VNet without public exposure.
  • B. Service Endpoints extend your VNet's identity to Azure service resources, allowing controlled access to PaaS services over the Azure backbone. However, they don't provide a private IP address for the PaaS service within your VNet, and traffic still goes through a public endpoint, albeit with VNet filtering.
  • D. A VPN Gateway connects on-premises networks to Azure VNets, or VNets to other VNets, over the public internet (with encryption) or private lines. It's not the most direct or simplified solution for connecting Azure App Service to a private PaaS database within Azure.

Azure Private Link

A service that provides private connectivity from an Azure virtual network to Azure PaaS services, customer-owned services, or Azure-hosted partner services. It uses private endpoints to bring services into your VNet, ensuring traffic stays on the Azure backbone.

  • Private connectivity to Azure PaaS services (e.g., SQL DB, Storage, Cosmos DB)
  • Traffic remains on the Azure backbone network
  • Bypasses the public internet
  • Uses private IP addresses within your VNet

Memory trick: Private Link is your personal Azure highway.

More Design security for applications and data questions