Your security team requires that apps run privately with no public inbound access and that all outbound traffic from the hosting environment use exactly one dedicated public IP that can be allowlisted on partner firewalls. You also need zone-redundant high availability. Which Azure App Service deployment option meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy an internal load balancer (ILB) App Service Environment v3 with zone redundancy, and attach an Azure NAT Gateway with a single public IP to the ASE subnet for dedicated egress..
Why this is the answer
An ILB App Service Environment v3 (ASEv3) provides private inbound access, and when configured with zone redundancy, it offers high availability. Attaching an Azure NAT Gateway to the ASE subnet ensures all outbound traffic uses a single, dedicated public IP address, meeting the egress requirement. External ASEv3s do not provide private inbound access. Multi-tenant App Service plans don't inherently offer a single dedicated egress IP without complex routing through Azure Firewall, which adds management overhead and may not be as straightforward for all outbound traffic. ASEv2 is a legacy option and doesn't support zone redundancy natively in the same way ASEv3 does, nor does it offer the same cost and performance benefits.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed