Azure Functions VNET Integration and NSG Control
You have an Azure subscription. The subscription contains a virtual network named VNet1 that contains the subnets shown in the following table. The subscription contains the function apps shown in the following table. The outbound traffic of which app is controlled by using NSG1? -
- 
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests knowledge of which Azure App Service tiers support VNET integration; the common trap is assuming Basic/Free tiers cannot use this feature, whereas Premium and Standard tiers can effectively bypass public internet exposure.
This question tests the capability of Azure Functions to integrate with Virtual Networks for secure outbound traffic access. It establishes that all listed function apps, regardless of their specific pricing tier shown in the diagram, can utilize VNET integration to route traffic through subnets protected by NSG1.
Candidates often select 'App4 only' (A) or exclude lower-tier apps, mistakenly believing that only the highest-tier app (App4, likely Premium v3 or Isolated) supports VNET integration, ignoring that Standard/Premium tiers also support it.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
All four applications (App1, App2, App3, and App4) are deployed on Azure Functions. Based on standard exam scenarios for AZ-500 involving VNET integration, these apps are configured to use Virtual Network Integration (or Gateway Required for Premium). This feature allows Function Apps running on supported plans (Standard, Premium, Premium v2, Premium v3) to send outbound traffic into a virtual network subnet. Since Subnet1, Subnet2, Subnet3, and Subnet4 are all associated with NSG1, any app integrated into these subnets will have its outbound traffic controlled by NSG1. The community consensus correctly identifies that if the apps are integrated, they all pass through the NSG.Why the Other Options Are Wrong
Option A (App4 only) assumes only the highest-tier app has VNET capabilities, which is incorrect as other Premium/Standard tiers support it. Option B and C exclude certain apps arbitrarily without evidence that those specific apps lack integration. In Azure security architecture, if an app is integrated into a VNet subnet, its traffic is subject to the NSGs attached to that subnet. Excluding apps implies they are not integrated, but the question context implies a uniform configuration or capability across the environment for testing VNET control.Community Comment Notes
Community members Viggy1212 and ITFranz referenced Microsoft documentation stating that Virtual Network Integration requires supported Basic or Standard, Premium, Premium v2, Premium v3, or Elastic Premium tiers. As ezmoney noted, "all the subnets... are associated with the same network security group (NSG1)", reinforcing that integration leads to NSG control. The majority voted D, confirming the interpretation that all apps are subject to the network controls via integration.Official Reference
Exam Strategy
When asked about VNET integration for App Services/Functions, remember that Standard, Premium, and higher tiers support it. If the question implies integration is active, all such apps' traffic is controlled by the NSGs of the target subnets. Do not assume Free/Basic tiers unless explicitly stated as unsupported.
Frequently Asked Questions
Do all Azure Functions tiers support VNET integration?
No. Only Basic, Standard, Premium, Premium v2, Premium v3, and Elastic Premium tiers support Virtual Network Integration. Free and Basic (older) may not.
How does NSG1 affect Function App traffic?
If a Function App uses VNET integration, its outbound traffic enters the specified subnet. NSGs attached to that subnet then filter this traffic.