Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy
A company is developing a new serverless application using Azure Functions. The application will process sensitive customer data and store it in Azure Cosmos DB. Security requirements mandate that all communication between the Azure Function and Cosmos DB must be encrypted end-to-end, and the Function must connect to Cosmos DB without exposing its network traffic to the public internet. Which Azure networking feature should be used to meet these requirements?
- AAzure Application Gateway
- BAzure Virtual Network Integration
- CAzure Front Door
- DAzure DNS Private Zones
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Virtual Network Integration
Azure Virtual Network (VNet) integration allows an Azure Function App to access resources within a VNet, ensuring that traffic between the Function and Cosmos DB (configured with VNet service endpoints or Private Link) remains within the private network and is not exposed to the public internet, fulfilling the security requirement.
Why the other options are wrong
- A. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. It does not provide private network integration for Azure Functions to backend services.
- C. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It does not provide private network integration for Azure Functions to backend services.
- D. Azure DNS Private Zones provide a reliable, secure DNS service for your virtual networks without the need to add a custom DNS solution. While important for private networking, it is not the feature that enables the Function's private network access itself.
Azure Virtual Network Integration for Functions
A feature that allows an Azure Function App to connect to resources within an Azure Virtual Network privately, ensuring traffic does not traverse the public internet.
- Enables outbound traffic from the Function App into a specified VNet.
- Used for secure access to resources like Azure SQL Database, Azure Storage, or Cosmos DB configured with private endpoints or service endpoints.
- Does not provide inbound access to the Function App from the VNet.
Memory trick: Functions need a VNet key to unlock private data doors.