Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard

A global e-commerce company uses Azure App Service to host its regional web applications. The company requires that all outbound traffic from these App Services to on-premises resources, which are connected via a VPN Gateway, must be routed through a specific Azure Virtual Network (VNet) and inspected by a Network Virtual Appliance (NVA) within that VNet. Which App Service networking feature, combined with appropriate VNet configuration, will ensure this outbound traffic flow?

  1. AAzure Front Door with custom origins
  2. BApp Service Environment (ASEv3)
  3. CApp Service VNet Integration (Gateway Required)
  4. DApp Service Private Endpoint
Show answer & explanation

Correct answer: C. App Service VNet Integration (Gateway Required)

App Service VNet Integration (Gateway Required) allows an App Service to send outbound traffic through a VNet's gateway, enabling it to reach on-premises resources connected via a VPN Gateway. Combined with UDRs in the VNet, this ensures traffic is routed through an NVA for inspection.

Why the other options are wrong

  • A. Azure Front Door is a global load balancer and WAF, primarily for inbound traffic management and acceleration, not for controlling outbound traffic from App Service to on-premises.
  • B. App Service Environment (ASEv3) deploys App Services directly into a VNet, providing full VNet networking capabilities, but VNet Integration (Gateway Required) is the specific feature for routing *outbound* traffic through a VNet's gateway for non-ASE App Services.
  • D. App Service Private Endpoint is for inbound private access to the App Service, not for controlling outbound traffic to on-premises.

App Service VNet Integration (Gateway Required)

A feature that allows an Azure App Service to route its outbound traffic through a specified Azure Virtual Network, enabling access to resources within that VNet or connected networks via a gateway.

  • Enables outbound traffic from App Service to flow into a VNet.
  • Supports routing to on-premises via VNet's VPN/ExpressRoute Gateway.
  • Requires a VNet Gateway for on-premises connectivity.
  • Can be combined with UDRs to force tunnel traffic through NVAs.

Memory trick: VNet Integration: Your App Service's private highway to on-prem.

More Secure data and applications questions