You will deploy an App Service app named App1 and use an existing Azure Front Door FD1 as the only way users should reach App1. Users must not be able to access App1 directly from the internet. What should you configure on App1 to meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: an access restriction.
Why this is the answer
Configuring an access restriction on App1 is the correct solution. This allows you to specify that only traffic originating from Azure Front Door's backend IP address ranges or its service tag (AzureFrontDoor.Backend) can reach App1. This ensures users can only access App1 through FD1, preventing direct internet access. A private endpoint would allow private access to App1 from a virtual network, but it doesn't restrict public internet access or enforce access through Front Door. Subnet delegation allows a subnet to delegate control to a specific Azure service, which is not relevant for restricting App Service access. A service endpoint enables secure and direct connectivity to Azure services from a virtual network, but it doesn't restrict incoming traffic to a specific Front Door instance.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed