Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A financial services company is deploying a new web application to Azure App Service that will process sensitive customer data. The application needs to connect securely to an Azure SQL Database. The security team mandates that all traffic between the App Service and the SQL Database must remain within the Azure backbone network and not traverse the public internet. Additionally, they require that the SQL Database is not publicly accessible. Which security feature should you configure for the Azure SQL Database to meet these requirements?
- AConfigure Microsoft Defender for SQL on the Azure SQL Database.
- BConfigure a firewall rule to allow traffic from the App Service's outbound IP addresses.
- CImplement an Azure Private Endpoint for the Azure SQL Database.
- DEnable Transparent Data Encryption (TDE) on the Azure SQL Database.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement an Azure Private Endpoint for the Azure SQL Database.
Azure Private Endpoint creates a private IP address for a resource within a virtual network, allowing private and secure access to the resource over the Azure backbone network, thus preventing public internet exposure. This directly addresses the requirement for secure, private connectivity and no public accessibility.
Why the other options are wrong
- A. Microsoft Defender for SQL provides vulnerability assessment and threat detection, but it does not control network access or prevent public internet exposure.
- B. Firewall rules control public access but do not ensure traffic stays on the Azure backbone or prevent public exposure of the database endpoint itself.
- D. TDE encrypts data at rest and in transit (within the database server), but it does not control network access or prevent public internet exposure.
Azure Private Endpoint
A network interface that connects you privately and securely to a service powered by Azure Private Link. Private Endpoint uses a private IP address from your VNet, effectively bringing the service into your VNet.
- Connects Azure services privately to your VNet.
- Traffic stays on the Azure backbone network.
- Eliminates public internet exposure for the service.
Memory trick: Private Endpoints keep services 'behind closed doors' in your VNet.