Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A startup is deploying its new web application to Azure App Service. The application is designed to be highly scalable and uses a serverless backend with Azure Functions. To minimize the attack surface and ensure that only trusted traffic can reach the App Service, the security team wants to restrict inbound access to the App Service to only specific IP addresses belonging to their corporate network and Azure Front Door. Which Azure App Service networking feature should be configured?
- APrivate Endpoints
- BVNet Integration
- CAccess Restrictions
- DService Endpoints
Show answer & explanationAnswer & explanation
Correct answer: C. Access Restrictions
App Service Access Restrictions allow you to define a prioritized list of IP addresses or Virtual Network subnets that are allowed or denied access to your application, directly addressing the requirement to restrict inbound traffic to specific IPs.
Why the other options are wrong
- A. Private Endpoints allow private access to the App Service from a VNet, but the question asks about restricting public inbound access to specific IPs.
- B. VNet Integration is for outbound traffic from App Service to a VNet, not for controlling inbound access.
- D. Service Endpoints allow a VNet subnet to securely access certain Azure services, but they don't control inbound access to an App Service itself from specified IPs.
Azure App Service Access Restrictions
A security feature in Azure App Service that allows you to define a prioritized list of allow/deny rules based on IP addresses, IP ranges, or virtual network subnets for inbound access to your web application.
- Controls inbound network traffic to the App Service.
- Supports IP addresses, CIDR blocks, and Service Tags (e.g., AzureFrontDoor.Backend).
- Rules are processed in priority order (lowest number first).
Memory trick: Access Restrictions are the bouncer at the App Service door.