Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A global e-commerce company uses Azure App Service to host its regional web applications. To enhance security and ensure that only authorized traffic from specific internal networks can reach the App Service, they need to restrict inbound access. The solution must allow for IP address-based filtering and VNet Service Endpoints. Which Azure App Service networking feature should be configured?
- AAzure Front Door with Web Application Firewall (WAF).
- BAzure Private Endpoint for App Service.
- CApp Service Access Restrictions.
- DApp Service Environment (ASEv3) with Network Security Groups (NSGs).
Show answer & explanationAnswer & explanation
Correct answer: C. App Service Access Restrictions.
App Service Access Restrictions allow you to define a prioritized list of IP address ranges or virtual network subnets that are allowed or denied access to your app. This feature directly supports IP-based filtering and VNet Service Endpoints for inbound access control.
Why the other options are wrong
- A. Azure Front Door with WAF focuses on global routing and web attack protection, not on restricting access from specific internal networks using IP ranges or VNet Service Endpoints directly at the App Service.
- B. Azure Private Endpoint provides private connectivity to the App Service, but the question specifically asks for IP address-based filtering and VNet Service Endpoints, which are handled by Access Restrictions.
- D. An App Service Environment (ASEv3) provides dedicated and isolated hosting, but 'Access Restrictions' is the specific feature within App Service (or ASE) that directly handles IP-based and VNet Service Endpoint filtering.
App Service Access Restrictions
A feature in Azure App Service that allows you to control inbound network access to your web app based on IP addresses, IP ranges, or virtual network subnets using VNet Service Endpoints.
- Configured directly on the App Service.
- Supports Allow/Deny rules based on IP addresses/ranges.
- Can integrate with VNet Service Endpoints for subnet-level access.
- Rules are evaluated in priority order.
Memory trick: Control who enters your App Service with a clear access list.