AZ-500 Secure networking Practice Question
Your company deploys a web application in an Azure App Service that needs to securely connect to an Azure SQL Database. You want to avoid exposing the database to the public internet. What is the recommended approach?
⚠ Common exam trap
Candidates often assume IP-based firewall rules (Option A) are sufficient for security, but Azure explicitly recommends private endpoints for PaaS services to avoid reliance on dynamic public IPs and to achieve true network isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a private endpoint for the SQL database and VNet integration for the App Service
It uses Azure Private Endpoint to place the Azure SQL Database on a virtual network, removing its public endpoint, and combines it with VNet integration for the App Service to route traffic through the same VNet. This ensures the database is never exposed to the public internet, meeting the security requirement without relying on IP-based firewall rules that can change or be spoofed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the SQL database firewall to allow only the App Service outbound IP
Why it's wrong here
Configuring the SQL database firewall to allow only the App Service's outbound IPs is inherently fragile: App Service outbound IPs can change when your app scales, moves, or is on a different plan, requiring constant rule updates. More importantly, this approach leaves the SQL database publicly endpoint-enabled, meaning the server is still reachable from the internet at that IP address. The firewall rule merely restricts source IPs, but the database is still exposed to arbitrary internet traffic from those permitted addresses, and any compromise or neighbor on a shared IP would break the intended isolation.
- ✗
Use Azure Firewall to block outbound traffic to the database
Why it's wrong here
Using Azure Firewall to block outbound traffic to the database attempts to control egress from your VNet, but it does nothing to protect the SQL database itself—the database's public endpoint remains fully exposed to the entire internet. Azure Firewall acts as a centralized filtering point, and to even apply it to an App Service you must configure VNet integration and forced tunneling, which adds complexity and does not reduce the attack surface of the PaaS endpoint. Since the database is still publicly resolvable and reachable, any other source (or a misconfigured rule) could still access it, so this is not a secure isolation mechanism.
- ✗
Create an NSG on the database subnet to deny internet traffic
Why it's wrong here
Creating an NSG on the database subnet is ineffective because Azure SQL Database does not reside in your subnet when using its public endpoint; it is a PaaS service hosted on Microsoft's infrastructure. NSGs only filter traffic entering or leaving virtual network subnets and NICs, so they have no bearing on the public IP address of the SQL database, which remains reachable from anywhere on the internet. Even if you deny all internet traffic from your subnet, the SQL endpoint is still accepting connections from the internet at large unless a separate firewall rule or public access setting is changed, so this approach fails to secure the database.
- ✓
Use a private endpoint for the SQL database and VNet integration for the App Service
Why this is correct
Using a private endpoint for the SQL database combined with VNet integration for the App Service is the correct approach because it removes the database's public endpoint entirely. The private endpoint assigns the SQL database a private IP address inside your VNet, and VNet Integration routes the App Service's traffic through that VNet, ensuring all communication stays within the Microsoft backbone and never traverses the public internet. After enabling the private endpoint, you can set the SQL server's public network access to 'Disabled', which fully blocks any internet-based access and leaves only the private connection. This provides a secure, stable, and compliant network path for the app-to-database traffic.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.