SC-100 · Question #24
Your company is designing an application architecture for Azure App Service Environment (ASE) web apps as shown in the exhibit. (Click the Exhibit tab.) Communication between the on-premises network…
The correct answer is D. Azure Firewall with policy rule sets. The on-premise firewall does not work for ExpressRoute connection. The on-prem app server is open to the public internet through the Azure network. To protect the app server, Azure Firewall with policy rule sets is needed to filter all types of traffic, while WAF works only for…
Question
Your company is designing an application architecture for Azure App Service Environment (ASE) web apps as shown in the exhibit. (Click the Exhibit tab.) Communication between the on-premises network and Azure uses an ExpressRoute connection. You need to recommend a solution to ensure that the web apps can communicate with the on- premises application server. The solution must minimize the number of public IP addresses that are allowed to access the on-premises network. What should you include in the recommendation?
Exhibit
Options
- AAzure Traffic Manager with priority traffic-routing methods
- BAzure Application Gateway v2 with user-defined routes (UDRs).
- CAzure Front Door with Azure Web Application Firewall (WAF)
- DAzure Firewall with policy rule sets
How the community answered
(26 responses)- A4% (1)
- B4% (1)
- C15% (4)
- D77% (20)
Explanation
The on-premise firewall does not work for ExpressRoute connection. The on-prem app server is open to the public internet through the Azure network. To protect the app server, Azure Firewall with policy rule sets is needed to filter all types of traffic, while WAF works only for web requests. In short, the Azure network needs a firewall. https://learn.microsoft.com/en-us/azure/app-service/environment/firewall-integration
Topics
Community Discussion
No community discussion yet for this question.
