A healthcare organization is migrating highly sensitive patient data to Azure. The data will be stored in Azure SQL Database and accessed by applications running in Azure App Service. Regulatory compliance mandates that all data in transit between these services must be encrypted and isolated from the public internet. Which solution should the security architect implement to meet these requirements?
- ADeploy Azure Front Door in front of App Service and use Azure Private DNS for SQL Database.
- BImplement Network Security Groups (NSGs) to restrict traffic between App Service and SQL Database.
- CConfigure App Service to use VNet integration and enable Private Link for Azure SQL Database.
- DEnsure HTTPS is enforced for App Service and enable Transparent Data Encryption (TDE) for Azure SQL Database.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure App Service to use VNet integration and enable Private Link for Azure SQL Database.
VNet integration for App Service allows the App Service to access resources in an Azure Virtual Network privately. Azure Private Link for Azure SQL Database creates a private endpoint for the database within a VNet, ensuring all traffic between App Service (via VNet integration) and SQL Database travels privately over the Microsoft backbone, encrypted, and isolated from the public internet.
Why the other options are wrong
- A. Azure Front Door is for global web traffic delivery and security; it's not for internal service-to-service communication isolation. Azure Private DNS resolves private endpoint FQDNs but doesn't provide the underlying private connectivity itself.
- B. NSGs provide L3/L4 traffic filtering but do not guarantee that traffic between App Service and SQL Database is isolated from the public internet. Without Private Link or service endpoints, traffic might still route over public IPs even if filtered.
- D. HTTPS enforces encryption for external web traffic to App Service. TDE encrypts data at rest in SQL Database. Neither explicitly isolates traffic between App Service and SQL DB from the public internet or ensures private connectivity between them.
Private Connectivity for PaaS
Azure Private Link and VNet Integration for App Service enable secure, private connectivity between Azure PaaS services and resources within a Virtual Network, ensuring data in transit is isolated from the public internet.
- Azure Private Link creates private endpoints for PaaS services.
- Traffic to private endpoints stays on the Microsoft backbone.
- VNet Integration allows App Service to access VNet resources.
- Ensures data in transit is encrypted and isolated from the public internet.
Memory trick: Private Link and VNet Integration secure your PaaS connections.