AZ-700 exam dumps

AZ-700 practice question 188 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 188

Select 2

You manage a multi-tier e-commerce application that uses an Azure App Service for the front-end. You deploy an Azure Application Gateway (WAF v2) to handle traffic for a custom domain over HTTPS and require end-to-end TLS encryption. You also want to ensure your Azure App Service only accepts traffic from the Application Gateway. Which two actions should you take to meet these requirements? (Choose two)

  1. A

    Configure a private endpoint for the Azure App Service and include the corresponding private IP address in the Application Gateway� backend pool.

  2. B

    Upload a trusted root certificate from your App Service to the Application Gateway and configure an HTTPS backend setting for end-to-end TLS re-encryption.

  3. C

    Enable 'Enforce HTTPS only' on the App Service and allow inbound traffic from all public IP addresses to avoid restricting legitimate connections.

  4. D

    Place the public IP address of the App Service in the Application Gateway� backend pool and configure SSL termination on the Application Gateway.

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirement of limiting inbound access to the App Service exclusively from the Application Gateway, you can configure a private endpoint for the App Service and reference that private IP in the Application Gateway� backend pool. Additionally, to fulfill end-to-end encryption, upload the trusted root certificate (or chain) from App Service to the Application Gateway to enable re-encryption of traffic from the gateway to the backend. For further details, refer to Microsoft� documentation on Azure Application Gateway end-to-end SSL (TLS) scenarios and private endpoint configuration (docs.microsoft.com/en-us/azure/application-gateway/tutorial-end-to-end-ssl and docs.microsoft.com/en-us/azure/app-service/networking/private-endpoint).

  • A. Correct.

    Option 1 is correct. By configuring a private endpoint for the Azure App Service and including its private IP address in the Application Gateway� backend pool, you ensure that traffic to the App Service can only come through the Application Gateway. This meets the requirement to limit access to requests originating from your Application Gateway.

  • B. Correct.

    Option 2 is correct. Uploading the trusted root certificate (often the App Service certificate chain) to the Application Gateway and configuring its backend pool settings for HTTPS re-encryption allows you to maintain TLS all the way to the App Service. This meets the end-to-end encryption requirement.

  • C. Incorrect.

    Option 3 is incorrect. While enabling 'Enforce HTTPS only' is a good security practice, allowing inbound traffic from all IP addresses does not restrict the App Service to receive traffic solely from the Application Gateway. This fails the requirement to limit access to your App Service.

  • D. Incorrect.

    Option 4 is incorrect. Configuring SSL termination at the Application Gateway means traffic is not re-encrypted before reaching the App Service. This does not achieve end-to-end TLS encryption. Additionally, using the public IP of the App Service would not restrict access to traffic originating from the Application Gateway alone.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam