Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A healthcare provider is developing a new patient portal application on Azure App Service. This application will store sensitive patient health information (PHI) in an Azure SQL Database. The security team mandates that the application's connection to the database must be entirely private, preventing any traffic from traversing the public internet, even within the Azure backbone. Furthermore, the database should not be directly accessible from the internet, and network access should be restricted to only the App Service instances. Which networking feature should the architect implement to secure the connection between Azure App Service and Azure SQL Database?
- AVirtual Network Integration
- BService Endpoints
- CAzure Private Link
- DNetwork Security Groups (NSGs)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Private Link
Azure Private Link provides private connectivity to Azure PaaS services like Azure SQL Database over a private endpoint in your virtual network. This ensures that all traffic between the App Service (integrated with a VNet) and the SQL Database remains entirely within the Azure backbone, never traversing the public internet, meeting the strict privacy requirement.
Why the other options are wrong
- A. Virtual Network Integration allows the App Service to access resources in a VNet but doesn't, by itself, make the connection to Azure SQL Database private; it needs to be combined with other features like Private Link or Service Endpoints.
- B. Service Endpoints extend your virtual network identity to Azure services, allowing access only from your VNet, but traffic still traverses the Azure backbone publicly, albeit restricted. It doesn't guarantee private connectivity.
- D. Network Security Groups (NSGs) filter network traffic to and from Azure resources but do not establish private connectivity or prevent traffic from traversing the public internet (even if restricted to specific IPs).
Azure Private Link
A service that provides private connectivity from an Azure virtual network to Azure PaaS services, customer-owned services, or Microsoft partner services, ensuring traffic flows entirely over the Microsoft backbone network.
- Establishes a private endpoint in your VNet for Azure services.
- Traffic remains on the Microsoft global network, bypassing the public internet.
- Simplifies network architecture and enhances security.
Memory trick: Private Link is your secret tunnel to Azure services, keeping everything off the public roads.