AZ-204 Implement Azure security Practice Question
Your company is deploying a multi-tier application on Azure. The application consists of a web front end, an API layer, and a database. You need to ensure secure communication between tiers. Which TWO actions should you take? (Choose two.)
⚠ Common exam trap
Many candidates confuse authentication (managed identities) with encryption (TLS), thinking that authenticating between tiers automatically secures the communication channel, when in fact encryption is required to protect data in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use TLS for all internal service-to-service communication
Option C is correct because using TLS for all internal service-to-service communication encrypts data in transit between the web front end, API layer, and database, preventing eavesdropping or tampering on the internal network. Option E is correct because NSGs act as stateful packet filters at the subnet/NIC level, and restricting traffic so only the web layer can reach the API layer and only the API layer can reach the database enforces least-privilege segmentation between tiers. Option A is not required by the scenario because HTTPS on the web front end only secures the external client-to-web path, not the internal tier-to-tier communication the question targets. Option B does not belong because Azure Storage encryption at rest protects stored data in Azure Storage, not the in-transit traffic between application tiers. Option D is not selected because managed identities provide authentication/authorization to Azure resources such as Key Vault or Azure SQL, but they do not by themselves secure or encrypt communication between the tiers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable HTTPS on the web front end
Why it's wrong here
Enabling HTTPS on the web front end primarily secures the communication channel between external clients and the public-facing web application. While crucial for protecting user data in transit from the internet, it does not inherently provide encryption or security for the internal service-to-service communication paths between the web layer, API layer, and database layer within the Azure virtual network. Therefore, it fails to address the security of data moving between internal application tiers.
- ✗
Enable Azure Storage encryption at rest
Why it's wrong here
Azure Storage encryption at rest, such as Server-Side Encryption for Blob storage or Azure Disk Encryption for virtual machine disks, protects data when it is persisted on storage devices. This measure is fundamental for data confidentiality when data is inactive or stored. However, it does not provide encryption for data as it actively travels across the network between different application tiers, which is the specific concern of securing data in transit.
- ✓
Use TLS for all internal service-to-service communication
Why this is correct
Transport Layer Security (TLS) is the industry-standard cryptographic protocol designed to provide end-to-end encryption and authentication for data in transit over a network. Implementing TLS for all internal service-to-service communication, such as between the web layer and API layer, and between the API layer and the database, directly addresses the requirement to secure data as it moves between application tiers. This ensures confidentiality, integrity, and authenticity of internal traffic, preventing eavesdropping and tampering.
- ✗
Use managed identities to authenticate between tiers
Why it's wrong here
Managed identities provide an Microsoft Entra ID (AAD) identity for Azure resources, enabling them to authenticate securely to other AAD-protected services without requiring developers to manage credentials. While essential for secure *authentication* and authorization between application tiers, managed identities do not inherently encrypt the *data payload* as it traverses the network. They establish *who* is communicating, but do not protect the content of the communication itself from interception.
- ✓
Configure network security groups (NSGs) to allow only the web layer to access the API layer, and only the API layer to access the database
Why this is correct
Network Security Groups (NSGs) operate at the network layer, allowing you to filter network traffic to and from Azure resources within an Azure Virtual Network based on IP addresses, ports, and protocols. By configuring NSGs to strictly control inbound and outbound traffic flows between specific tiers, you enforce network segmentation and restrict unauthorized access. This ensures that only legitimate communication paths are established (e.g., web to API, API to database), significantly reducing the attack surface by preventing direct access to backend tiers from unintended sources.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.