Courseiva

How to Secure Azure App Service Environment for FedRAMP High Compliance

A government agency, Northwind, is deploying a sensitive application on Azure App Service Environment (ASE) v3. The application handles classified data and must meet FedRAMP High requirements. You need to design a security solution that includes: (1) encryption at rest for the app's content and configuration, (2) encryption in transit with TLS 1.2 or higher, (3) network isolation using VNet integration and private endpoints, (4) identity-based access to Azure SQL Database using managed identity, and (5) certificate management for custom domains using Azure Key Vault. Which of the following designs meets all requirements?

Quick Answer

The correct design deploys the app on an Azure App Service Environment v3 within a VNet, enforces HTTPS only with TLS 1.2, uses a system-assigned managed identity to access Azure SQL Database, and configures TLS/SSL certificates from Azure Key Vault. This meets all FedRAMP High requirements because ASE v3 inherently provides network isolation through VNet deployment, while managed identity eliminates the need for stored credentials, and Key Vault integration handles certificate lifecycle securely. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how to secure Azure App Service Environment for FedRAMP High compliance by combining platform-level isolation with identity-based access—a common trap is confusing VNet integration (outbound only) with private endpoints (inbound isolation). Remember the mnemonic “VNet, TLS, MI, KV” to recall the four pillars: VNet isolation, enforced TLS 1.2, managed identity for SQL, and Key Vault for certificates.

⚠ Common exam trap

SC-100 often tests the assumption that multi-tenant App Service with TLS and managed identity is 'good enough' for high-compliance workloads, when the exam expects recognition that single-tenant ASE v3 plus Key Vault-backed certificates is mandatory for FedRAMP High isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.

ASE v3 provides a fully isolated, single-tenant App Service environment deployed into a customer VNet, which is required for FedRAMP High and network isolation. It also correctly combines HTTPS-only with TLS 1.2, a system-assigned managed identity for passwordless Azure SQL authentication, and Key Vault for certificate management — all of which are supported natively in ASE v3. The other options either use multi-tenant App Service (not isolated) or substitute components that don't meet the full requirement set.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the app on a multi-tenant App Service plan, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.

    Why it's wrong here

    A multi-tenant App Service plan provides no VNet isolation or private endpoints, failing requirement three. It is tempting because system-assigned managed identity and Key Vault certificates satisfy other items, but only an ASE v3 delivers the dedicated, network-isolated hosting FedRAMP High demands.

  • ✓

    Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.

    Why this is correct

    ASE v3 provides the isolated VNet deployment, HTTPS-only with TLS 1.2 satisfies encryption in transit, the system-assigned managed identity enables passwordless Microsoft Entra ID authentication to Azure SQL Database, and Key Vault supplies the custom-domain certificates, meeting every stated constraint.

  • ✗

    Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a user-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from App Service certificates.

    Why it's wrong here

    App Service certificates are stored in the App Service resource, not Azure Key Vault, so requirement five fails. Key Vault is tempting because it centralises secrets and supports customer-managed keys, but App Service certificates cannot satisfy the mandated Key Vault certificate management for custom domains.

  • ✗

    Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a service principal to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.

    Why it's wrong here

    A service principal authenticates with a client secret or certificate stored outside the app, whereas managed identity removes that credential entirely. Service principals are tempting for automation across tenants, but requirement four explicitly mandates managed identity for Azure SQL Database access.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company deploys a line-of-business application on Azure App Service. The application uses a managed identity to access Azure SQL Database. Security policy requires that the database connection string must not contain credentials. How should the connection string be configured?

medium
  • A.Store the connection string in App Service application settings with the password encrypted by App Service
  • B.Store the connection string with username and password in Key Vault and reference it in App Settings
  • ✓ C.Use a managed identity and set the connection string to use Active Directory Managed Identity authentication without credentials
  • D.Store the connection string as a secret in Azure Key Vault and use a Key Vault reference in App Settings

Why C: Using a managed identity, the connection string can be set to use 'Authentication=Active Directory Managed Identity' without any username or password. Option A is wrong because the connection string should not include credentials. Option B is wrong because Key Vault references are used for secrets, but managed identity itself avoids the need for a secret. Option D is wrong because connection strings are not stored in App Service as secrets.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.