Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A financial services company is deploying a new web application to Azure App Service that will process sensitive customer data. The company requires that all network traffic to and from the App Service instance is routed exclusively through a private network, without exposure to the public internet. Which Azure networking feature should be implemented to meet this requirement?
- ANetwork Security Groups (NSGs)
- BApp Service Private Endpoint
- CApp Service VNet Integration (Gateway Required)
- DAzure Front Door
Show answer & explanationAnswer & explanation
Correct answer: B. App Service Private Endpoint
App Service Private Endpoint allows an Azure App Service to be accessed privately from a virtual network, ensuring that traffic does not traverse the public internet. This meets the requirement for exclusive private network routing.
Why the other options are wrong
- A. Network Security Groups (NSGs) filter network traffic to and from Azure resources within an Azure VNet but do not inherently make an App Service private without other mechanisms.
- C. VNet Integration (Gateway Required) allows outbound traffic from App Service to flow through a VNet, but it doesn't restrict inbound public access.
- D. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, which does not inherently restrict traffic to a private network.
App Service Private Endpoint
A networking feature that allows Azure App Service to be accessed privately from a virtual network, eliminating public internet exposure.
- Provides a private IP address for the App Service within a VNet.
- Ensures all traffic (inbound and outbound) flows through the VNet.
- Enhances security by removing public internet access.
Memory trick: Private Endpoint: Your App Service's VIP private party.