Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard
A developer is building an Azure Function App that processes sensitive customer data. The Function App needs to connect to an SFTP server hosted on-premises within the corporate network. The corporate network has strict firewall rules and only allows outbound connections from specific IP ranges. Which networking feature should be configured for the Azure Function App to enable secure and controlled access to the on-premises SFTP server?
- AAzure Virtual Network Integration
- BAzure Firewall
- CAzure Public IP Address
- DService Endpoints
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Virtual Network Integration
Azure Virtual Network (VNet) integration for Azure Functions allows the Function App to send outbound traffic into a specified VNet. This VNet can then be connected to the on-premises network via a VPN Gateway or ExpressRoute, enabling the Function App to access the SFTP server. This ensures that the outbound traffic originates from a predictable IP range within the VNet, which can be whitelisted by the on-premises firewall.
Why the other options are wrong
- B. Azure Firewall is a managed cloud-based network security service that protects your Azure Virtual Network resources. While it could be used within the VNet, VNet integration is the prerequisite for the Function App to use the VNet's outbound path.
- C. Azure Public IP Address is for inbound access or for resources that need a stable, public outbound IP. While a Function App can have static outbound IPs, VNet integration is required to route traffic through a private network connection to on-premises.
- D. Service Endpoints provide secure and direct connectivity to Azure services over the Azure backbone network. They are for connecting to other Azure PaaS services, not for connecting to on-premises resources.
Azure Functions VNet Integration
A networking feature that enables an Azure Function App to connect to resources within an Azure Virtual Network, facilitating private and secure outbound communication.
- Routes outbound traffic from the Function App through a designated subnet in a VNet.
- Allows access to resources in the VNet, peered VNets, and on-premises networks (via VPN/ExpressRoute).
- Ensures outbound traffic originates from predictable, VNet-controlled IP addresses.
Memory trick: VNet is the bridge for Functions to reach on-prem islands.