A financial services company is deploying a new web application to Azure App Service that will process sensitive customer financial data. The application must establish a private and secure connection to an Azure SQL Database, ensuring that traffic between the App Service and the SQL Database does not traverse the public internet. Which networking feature should be configured for the App Service?
- AHybrid Connections for secure database access.
- BApp Service Access Restrictions with VNet service endpoints.
- CApp Service Private Endpoint.
- DVNet Integration (Regional) with Network Security Groups (NSGs).
Show answer & explanationAnswer & explanation
Correct answer: C. App Service Private Endpoint.
An App Service Private Endpoint creates a private IP address for the App Service within a virtual network. This allows the App Service to connect to other Azure services, like Azure SQL Database, over a private link, ensuring that traffic between them does not traverse the public internet, directly meeting the requirement for private and secure connectivity.
Why the other options are wrong
- A. Hybrid Connections are typically used for connecting to on-premises resources, not for private connectivity between Azure App Service and Azure SQL Database within Azure.
- B. App Service Access Restrictions with VNet service endpoints are for controlling *inbound* access to the App Service, not for enabling the App Service to make *outbound* private connections to other Azure services.
- D. VNet Integration (Regional) allows the App Service to make outbound calls into a VNet, but for inbound calls or private access to other Azure services *from* the App Service *to* the service's private endpoint, the App Service needs its own private endpoint or the SQL DB needs a private endpoint and the App Service needs to be in the VNet. The question implies a private link for the App Service itself to access the SQL DB privately.
App Service Private Endpoint
A networking feature that provisions a private IP address for an Azure App Service within a specified Azure Virtual Network, enabling secure and private access to the App Service from the VNet and allowing the App Service to connect privately to other Azure services with Private Endpoints.
- Establishes a private link connection to the App Service.
- Traffic bypasses the public internet.
- Enhances security for inbound and outbound connections.
- Requires a Virtual Network for deployment.
Memory trick: Give your App Service a private gate to talk to other Azure services.