Nimbus Cloud runs a network security perimeter (NSP) architecture and needs to include Platform-as-a-Service (PaaS) resources such as Azure Storage and Azure SQL in the perimeter. The security requirement is that all management plane and data-plane access to these PaaS services must either originate from the NSP hub or be blocked. Which approach ensures PaaS resources are associated with the NSP while allowing secure access from the hub?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Private Endpoints for Azure Storage and Azure SQL in the NSP hub or linked VNets, restrict public access on the PaaS resources, and configure service endpoints or routing so that management and data-plane traffic flows through the NSP hub..
Why this is the answer
Private Endpoints are the correct solution because they bring PaaS services into your private network, making them accessible only through your Azure VNet. By deploying Private Endpoints within the NSP hub or linked VNets, you ensure that all traffic (both management and data plane) to these PaaS resources traverses the NSP, satisfying the security requirement. Restricting public access on the PaaS resources further enhances security by eliminating external exposure. Service endpoints or routing configurations then direct traffic through the NSP hub. Enabling firewall rules on PaaS resources with public IPs is less secure as it still exposes the services publicly. Deploying PaaS resources inside VNets (VNet-injection) is not universally supported for all PaaS services and doesn't inherently enforce NSP traversal for all traffic. Using Azure Front Door is primarily for web application delivery and load balancing, not for integrating all PaaS services into a private network security perimeter.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed