Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A company is deploying a new web application to Azure App Service. The application needs to perform outbound network calls to an on-premises database through an Azure Virtual Network (VNet) gateway. To ensure that these outbound calls originate from a static, known IP address for firewall whitelisting on-premises, which Azure networking feature should be implemented?
- ANetwork Security Group (NSG)
- BAzure DNS Private Zones
- CVNet Integration with Gateway required routing
- DAzure Private Link
Show answer & explanationAnswer & explanation
Correct answer: C. VNet Integration with Gateway required routing
VNet integration with 'Gateway required routing' ensures that all outbound traffic from the App Service is routed through the associated VNet and its gateway. This allows the on-premises firewall to whitelist a single, static public IP address associated with the VNet gateway.
Why the other options are wrong
- A. NSGs filter traffic but do not provide a static outbound IP for App Service to on-premises communication.
- B. Azure DNS Private Zones manage name resolution within a VNet but do not control outbound IP addresses.
- D. Azure Private Link is for inbound private access to Azure services, not outbound from App Service to on-premises.
App Service VNet Integration (Gateway required)
A feature that allows an Azure App Service app to access resources in an Azure Virtual Network, routing all outbound traffic through the VNet's gateway for static egress IP addresses.
- Enables App Service to access resources in a VNet.
- Gateway required routing forces all outbound traffic through the VNet gateway.
- Provides a static, known outbound IP address for App Service.
Memory trick: App Service wants to go home, but needs a fixed address to get through the gate.