Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A company is developing an Azure Function App that needs to connect to an SFTP server hosted on a virtual machine within an Azure Virtual Network (VNet). The SFTP server is only accessible from within the VNet. The Azure Function App is deployed to a Consumption Plan. Which networking configuration is required to enable the Azure Function App to securely connect to the SFTP server while maintaining the serverless benefits of the Consumption Plan?

  1. AConfigure a Service Endpoint for the Azure Function App to the VNet.
  2. BDeploy the Azure Function App into an Azure App Service Environment (ASE) v3 within the VNet.
  3. CCreate a Site-to-Site VPN connection between the Azure Function App and the VNet.
  4. DIntegrate the Azure Function App with the Azure Virtual Network using VNet Integration.
Show answer & explanation

Correct answer: D. Integrate the Azure Function App with the Azure Virtual Network using VNet Integration.

VNet Integration allows a Function App (including those on Consumption Plans) to access resources within a VNet. It routes outbound traffic from the Function App into the specified VNet, enabling secure communication with resources like the SFTP server, without requiring an App Service Environment.

Why the other options are wrong

  • A. Service Endpoints are for securing inbound traffic to Azure services from a VNet, not for outbound access from a Function App into a VNet to custom resources.
  • B. App Service Environment (ASE) v3 provides full VNet isolation but is a dedicated, expensive offering. VNet Integration achieves the goal for Consumption Plan Functions without the ASE cost.
  • C. A Site-to-Site VPN is for connecting on-premises networks to Azure VNets, or two VNets together. It's not the mechanism for a Function App to connect into a VNet directly.

Azure Functions VNet Integration

A feature that allows an Azure Function App to connect to resources within an Azure Virtual Network, routing its outbound traffic through the VNet.

  • Works with Consumption, Premium, and Dedicated plans.
  • Enables access to private endpoints, service endpoints, and custom resources in VNet.
  • Does not provide inbound VNet access to the Function App.
  • Simplified networking for serverless applications.

Memory trick: To reach inside the VNet, the Function needs VNet Integration.

More Implement Azure security questions