Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium

A company is deploying an internal web application on Azure Virtual Machines (VMs). The application needs to be accessible only from within the corporate network, which is connected to Azure via a Site-to-Site VPN. You must ensure that the public IP address of the web application is not discoverable from the internet and that all traffic remains within Azure's private network.

  1. AAssign a private IP address to the VM and place it behind an Internal Azure Load Balancer.
  2. BAssign a public IP address to the VM and configure a Network Security Group (NSG) to restrict access.
  3. CPlace the VM behind an Azure Public Load Balancer and configure NSG rules.
  4. DAssign a private IP address to the VM and use Azure Private DNS for name resolution.
Show answer & explanation

Correct answer: A. Assign a private IP address to the VM and place it behind an Internal Azure Load Balancer.

To ensure the web application is only accessible privately and its public IP is not discoverable, the VM should use a private IP address. An Internal Azure Load Balancer can then distribute traffic to these private IP VMs, making the application accessible only from within the VNet or connected networks (like the corporate network via VPN).

Why the other options are wrong

  • B. Assigning a public IP makes it discoverable from the internet, which violates a key requirement.
  • C. A Public Load Balancer exposes a public IP address, which violates the requirement for no internet discoverability.
  • D. Assigning a private IP and using Private DNS is good for internal access, but a load balancer is often needed for distributing traffic to multiple VMs and providing a single entry point for the application.

Internal Azure Load Balancer

An Internal Azure Load Balancer distributes incoming traffic among virtual machines within a virtual network or a hybrid network connected via VPN/ExpressRoute, without exposing a public IP address.

  • Only accessible from within the VNet or connected private networks.
  • Does not have a public IP address.
  • Used for load balancing internal L4 (TCP/UDP) traffic.

Memory trick: Keep it internal, keep it private, keep it balanced.

More Implement and manage virtual networking questions