Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A company is deploying a new application that uses Azure Key Vault to store cryptographic keys and secrets. The security architect needs to ensure that access to Key Vault is restricted to only authorized Azure resources (e.g., Azure App Service, Azure Functions) and prevents access from the public internet, even if a resource has an incorrect configuration. Which Key Vault networking feature should be configured?

  1. AAzure Private Link.
  2. BAzure DDoS Protection Standard.
  3. CVirtual Network service endpoints.
  4. DPublic endpoint with IP firewall rules.
Show answer & explanation

Correct answer: A. Azure Private Link.

Azure Private Link creates a private endpoint for the Key Vault within a virtual network. This ensures that access to the Key Vault is exclusively via a private IP address within the VNet, effectively isolating it from the public internet and providing a secure, private connection for authorized Azure resources.

Why the other options are wrong

  • B. Azure DDoS Protection Standard protects public IP resources against distributed denial-of-service attacks. It does not provide private connectivity or restrict access to Key Vault from the public internet.
  • C. Virtual Network service endpoints extend your VNet's identity to Azure services, allowing private access from a VNet. However, for Key Vault, Private Link offers a more robust and isolated solution by creating a private IP address for the Key Vault itself within the VNet, providing true private connectivity.
  • D. Public endpoint with IP firewall rules restricts access based on source IP addresses. While it limits public access, it still uses the public endpoint and relies on correct IP configuration, which can be prone to misconfiguration and doesn't fully 'prevent access from the public internet' for the service itself.

Azure Private Link for Key Vault

A networking service that provides private connectivity to Azure Key Vault from a virtual network, allowing secure access over a private endpoint and isolating the Key Vault from the public internet.

  • Creates a private endpoint in your VNet for Key Vault.
  • Access to Key Vault via private IP address only.
  • Traffic stays on the Microsoft backbone.
  • Enhances security by eliminating public internet exposure.

Memory trick: Private Link keeps Key Vault Private from the Public.

More Design security for infrastructure questions