How to Secure Azure App Service Environment for FedRAMP High Compliance
A government agency, Northwind, is deploying a sensitive application on Azure App Service Environment (ASE) v3. The application handles classified data and must meet FedRAMP High requirements. You need to design a security solution that includes: (1) encryption at rest for the app's content and configuration, (2) encryption in transit with TLS 1.2 or higher, (3) network isolation using VNet integration and private endpoints, (4) identity-based access to Azure SQL Database using managed identity, and (5) certificate management for custom domains using Azure Key Vault. Which of the following designs meets all requirements?
Quick Answer
The correct design deploys the app on an Azure App Service Environment v3 within a VNet, enforces HTTPS only with TLS 1.2, uses a system-assigned managed identity to access Azure SQL Database, and configures TLS/SSL certificates from Azure Key Vault. This meets all FedRAMP High requirements because ASE v3 inherently provides network isolation through VNet deployment, while managed identity eliminates the need for stored credentials, and Key Vault integration handles certificate lifecycle securely. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how to secure Azure App Service Environment for FedRAMP High compliance by combining platform-level isolation with identity-based access—a common trap is confusing VNet integration (outbound only) with private endpoints (inbound isolation). Remember the mnemonic “VNet, TLS, MI, KV” to recall the four pillars: VNet isolation, enforced TLS 1.2, managed identity for SQL, and Key Vault for certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
ASE v3 is deployed in a VNet, providing network isolation. Enforcing HTTPS only with TLS 1.2 ensures encryption in transit. Using system-assigned managed identity allows identity-based access to Azure SQL Database. TLS/SSL certificates from Azure Key Vault support certificate management. Option A is wrong because a multi-tenant App Service plan does not provide network isolation, failing the VNet integration requirement. Option C is wrong because App Service certificates are not managed via Key Vault, failing the certificate management requirement. Option D is wrong because service principal is less secure than managed identity and does not meet the identity-based access requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the app on a multi-tenant App Service plan, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
Why it's wrong here
Multi-tenant App Service does not provide network isolation; the app is exposed to the internet.
- ✓
Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
Why this is correct
ASE v3 provides network isolation, managed identity provides secure database access, and Key Vault handles certificates.
- ✗
Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a user-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from App Service certificates.
Why it's wrong here
App Service certificates are not stored in Key Vault by default. Managed identity can be either system or user; both are fine, but the requirement mentions Key Vault for certificates.
- ✗
Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a service principal to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
Why it's wrong here
Service principal is less secure than managed identity because it requires credential management.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company deploys a line-of-business application on Azure App Service. The application uses a managed identity to access Azure SQL Database. Security policy requires that the database connection string must not contain credentials. How should the connection string be configured?
medium- A.Store the connection string in App Service application settings with the password encrypted by App Service
- B.Store the connection string with username and password in Key Vault and reference it in App Settings
- ✓ C.Use a managed identity and set the connection string to use Active Directory Managed Identity authentication without credentials
- D.Store the connection string as a secret in Azure Key Vault and use a Key Vault reference in App Settings
Why C: Using a managed identity, the connection string can be set to use 'Authentication=Active Directory Managed Identity' without any username or password. Option A is wrong because the connection string should not include credentials. Option B is wrong because Key Vault references are used for secrets, but managed identity itself avoids the need for a secret. Option D is wrong because connection strings are not stored in App Service as secrets.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.