Microsoft Certified: Azure Administrator AssociateDeploy and manage Azure compute resourcesHard

A company is deploying a new application to Azure App Service. The application is sensitive and requires all outbound network traffic from the App Service to be routed through a firewall appliance hosted in a virtual network (VNet) for inspection and auditing. Which networking feature must be enabled and configured for the App Service?

  1. AAccess Restrictions
  2. BVirtual Network Integration
  3. CPrivate Endpoint
  4. DService Endpoints
Show answer & explanation

Correct answer: B. Virtual Network Integration

Virtual Network Integration allows the App Service to join a VNet, enabling all outbound traffic to be routed through the VNet. Combined with a VNet route table that forwards all outbound traffic to a firewall appliance, this satisfies the requirement.

Why the other options are wrong

  • A. Access Restrictions control inbound traffic to the App Service, not outbound traffic from it.
  • C. Private Endpoint is for securing inbound access to an Azure service from a VNet, not for routing outbound traffic from an App Service through a firewall.
  • D. Service Endpoints secure direct connectivity to specific Azure services (like Storage or SQL Database) over the Azure backbone, but they don't route general outbound internet traffic through a firewall.

App Service VNet Integration (Outbound Routing)

A feature that connects an Azure App Service to a Virtual Network, allowing outbound traffic from the App Service to be routed through the VNet. This enables access to VNet resources and control over outbound internet access via NVA/firewall.

  • Enables outbound traffic from App Service to flow into a VNet
  • Can be combined with User Defined Routes (UDRs)
  • Allows forcing all outbound traffic through an NVA/firewall
  • App Service gets a private IP within the VNet for outbound access

Memory trick: Integrate VNet to Intercept Outbound.

More Deploy and manage Azure compute resources questions