Microsoft Certified: Azure Administrator AssociateDeploy and manage Azure compute resourcesMedium

A company is deploying a new multi-tier application to Azure. The application consists of a web front-end, a business logic tier, and a database tier. The business logic tier runs on several Azure virtual machines (VMs) that need to communicate with each other and with the database, but should not be directly accessible from the internet. You need to design the network connectivity for the business logic tier.

  1. APlace the business logic VMs in a private subnet and configure a Public IP address for each VM.
  2. BPlace the business logic VMs in a public subnet and apply Network Security Groups (NSGs) to restrict inbound internet access.
  3. CPlace the business logic VMs in a public subnet and use Azure Firewall to block all internet inbound traffic.
  4. DPlace the business logic VMs in a private subnet within an Azure Virtual Network (VNet) and use NSGs to control internal traffic.
Show answer & explanation

Correct answer: D. Place the business logic VMs in a private subnet within an Azure Virtual Network (VNet) and use NSGs to control internal traffic.

Placing the business logic VMs in a private subnet ensures they are not directly exposed to the internet. Using NSGs allows for granular control over traffic between VMs within the VNet and to other internal resources like the database, fulfilling the communication and security requirements.

Why the other options are wrong

  • A. Assigning Public IP addresses defeats the purpose of a private subnet and exposes the VMs directly.
  • B. Placing VMs in a public subnet inherently exposes them, even with NSGs, which is less secure than a private subnet.
  • C. While Azure Firewall can block traffic, placing the VMs in a public subnet is still less secure by design than a private subnet, and Firewall is often an additional layer for VNet egress/ingress, not a primary isolation mechanism for internal tiers.

Azure Private Subnet

A segment of an Azure Virtual Network (VNet) where resources are not directly accessible from the internet by default, providing an isolated network environment for internal applications.

  • Resources within can communicate with each other and other VNet resources.
  • Requires Network Security Groups (NSGs) for granular traffic control.
  • Enhances security by limiting internet exposure.
  • Can be connected to on-premises networks via VPN/ExpressRoute.

Memory trick: Private Subnets Protect Internal Paths.

More Deploy and manage Azure compute resources questions