Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A healthcare provider is deploying a new patient portal application to Azure App Service. The application needs to securely connect to an Azure SQL Database instance that hosts sensitive patient health information (PHI). To enhance security and restrict network access, the database should not be accessible over the public internet, and all traffic between the App Service and SQL Database must remain within the Azure backbone network. Which networking solution should the architect implement?
- AService Endpoints for Azure SQL Database
- BVirtual Network Integration for App Service
- CPrivate Link for Azure SQL Database
- DNetwork Security Groups (NSGs) for the SQL Database subnet
Show answer & explanationAnswer & explanation
Correct answer: C. Private Link for Azure SQL Database
Azure Private Link creates a private endpoint for the Azure SQL Database within the virtual network. This allows the App Service, when integrated into the same or peered VNet, to connect to the SQL Database privately over the Azure backbone network, completely isolating it from the public internet.
Why the other options are wrong
- A. Service Endpoints allow traffic to remain on the Azure backbone but still use the public IP address of the service. While it restricts access to specific VNets, it doesn't give the database a private IP within the VNet, and the requirement is for the database to *not* be accessible over the public internet.
- B. Virtual Network Integration for App Service allows the App Service to access resources in a VNet, but it doesn't by itself make the SQL Database private or inaccessible from the public internet.
- D. NSGs can filter traffic to the SQL Database, but they don't remove its public endpoint or ensure traffic remains entirely private if the database is still exposed publicly.
Azure Private Link
A service that enables you to access Azure PaaS Services (e.g., Azure SQL Database, Azure Storage) and Azure hosted customer/partner services over a private endpoint in your virtual network, keeping traffic entirely on the Azure backbone network.
- Exposes Azure PaaS services via a private IP address within your VNet.
- Traffic remains entirely on the Azure backbone network.
- Eliminates public internet exposure for PaaS services.
- Simplifies network architecture and enhances security.
Memory trick: Private Link: Your private road to Azure services.