Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard
A global e-commerce company uses Azure App Service to host its regional web applications. The company requires that all outbound traffic from these App Services to on-premises resources, which are connected via a VPN Gateway, must be routed through a specific Azure Virtual Network (VNet) and inspected by a Network Virtual Appliance (NVA) within that VNet. Which App Service networking feature, combined with appropriate VNet configuration, will ensure this outbound traffic flow?
- AAzure Front Door with custom origins
- BApp Service Environment (ASEv3)
- CApp Service VNet Integration (Gateway Required)
- DApp Service Private Endpoint
Show answer & explanationAnswer & explanation
Correct answer: C. App Service VNet Integration (Gateway Required)
App Service VNet Integration (Gateway Required) allows an App Service to send outbound traffic through a VNet's gateway, enabling it to reach on-premises resources connected via a VPN Gateway. Combined with UDRs in the VNet, this ensures traffic is routed through an NVA for inspection.
Why the other options are wrong
- A. Azure Front Door is a global load balancer and WAF, primarily for inbound traffic management and acceleration, not for controlling outbound traffic from App Service to on-premises.
- B. App Service Environment (ASEv3) deploys App Services directly into a VNet, providing full VNet networking capabilities, but VNet Integration (Gateway Required) is the specific feature for routing *outbound* traffic through a VNet's gateway for non-ASE App Services.
- D. App Service Private Endpoint is for inbound private access to the App Service, not for controlling outbound traffic to on-premises.
App Service VNet Integration (Gateway Required)
A feature that allows an Azure App Service to route its outbound traffic through a specified Azure Virtual Network, enabling access to resources within that VNet or connected networks via a gateway.
- Enables outbound traffic from App Service to flow into a VNet.
- Supports routing to on-premises via VNet's VPN/ExpressRoute Gateway.
- Requires a VNet Gateway for on-premises connectivity.
- Can be combined with UDRs to force tunnel traffic through NVAs.
Memory trick: VNet Integration: Your App Service's private highway to on-prem.