Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium
A company is migrating its on-premises web application to Azure. The application's backend database is hosted on an Azure SQL Database. The security team requires that the Azure SQL Database be accessible only from the application's virtual machines (VMs) within a specific subnet, and no traffic should traverse the public internet. Which Azure networking feature should you implement to meet this requirement?
- AAzure Firewall
- BService Endpoints
- CNetwork Security Group (NSG)
- DAzure Private Link
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Private Link
Azure Private Link allows you to access Azure PaaS services (like Azure SQL Database) over a private endpoint in your virtual network. This ensures that traffic between your VMs and the Azure SQL Database remains entirely within the Microsoft backbone network, never traversing the public internet, and is only accessible from your specified VNet.
Why the other options are wrong
- A. Azure Firewall protects your VNet resources by filtering traffic, but it doesn't inherently make a public PaaS service private, nor does it prevent traffic from traversing the public internet if the service is accessed via its public endpoint.
- B. Service Endpoints allow your VNet to connect directly to Azure services over the Azure backbone network. While it keeps traffic off the public internet, the service endpoint itself is publicly routable, and access control is typically at the subnet level, not a private IP.
- C. An NSG can control outbound traffic from your VMs, but it doesn't prevent the Azure SQL Database from being accessible via its public endpoint, nor does it guarantee traffic stays off the public internet if the database is accessed publicly.
Azure Private Link
A service that enables private access to Azure PaaS services (e.g., Azure Storage, Azure SQL Database) and customer-owned/partner services over a private endpoint in your virtual network.
- Traffic travels over the Microsoft global network, not the public internet.
- The private endpoint maps to a private IP address in your VNet.
- Provides secure and isolated access to Azure services.
Memory trick: Private Link: Your PaaS has its own personal, private lane.