Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A healthcare provider is deploying a new patient portal application to Azure App Service. The application will store patient health records (PHR) in Azure Cosmos DB and images in Azure Blob Storage. The security architect needs to ensure that all data access from the App Service to these backend services is secured using private networking, eliminating exposure to the public internet, to comply with HIPAA regulations. Which Azure networking feature is most appropriate for achieving this private connectivity?

  1. AAzure Virtual Network Service Endpoints for both Azure Cosmos DB and Azure Blob Storage.
  2. BAzure Application Gateway with Web Application Firewall (WAF) for inbound traffic.
  3. CAzure Network Security Groups (NSGs) applied to the App Service subnet and backend services.
  4. DAzure Private Link for both Azure Cosmos DB and Azure Blob Storage.
Show answer & explanation

Correct answer: D. Azure Private Link for both Azure Cosmos DB and Azure Blob Storage.

Azure Private Link creates a private endpoint in your virtual network for accessing Azure PaaS services like Cosmos DB and Blob Storage, ensuring traffic flows over the Microsoft backbone network and is not exposed to the public internet.

Why the other options are wrong

  • A. Service Endpoints provide secure and direct connectivity to Azure services over the Azure backbone network. While they enhance security, Private Link offers a more comprehensive private networking solution by bringing the service into the VNet with a private IP address, fully eliminating public internet exposure for the data plane, which is often preferred for strict compliance like HIPAA.
  • B. Application Gateway with WAF protects inbound web traffic to the App Service but does not secure the outbound connection from App Service to backend PaaS services privately.
  • C. NSGs filter network traffic but do not create private connectivity for PaaS services; traffic would still traverse public endpoints.

Azure Private Link

A service that enables you to access Azure PaaS services (for example, Azure Storage and Azure Cosmos DB) and Azure hosted customer-owned/partner services over a private endpoint in your virtual network.

  • Traffic between your VNet and the service travels over the Microsoft backbone network.
  • Eliminates public internet exposure.
  • Simplifies network architecture and enhances security.

Memory trick: Private Link: Your Private Lane to PaaS.

More Design security for applications and data questions