Azure Functions VNET Integration and NSG Control

Plan and implement security for virtual networks
Answer Correct answer: D — All function apps (App1, App2, App3, and App4) have outbound traffic controlled by NSG1 because they are integrated into the virtual network subnets associated with that NSG.

You have an Azure subscription. The subscription contains a virtual network named VNet1 that contains the subnets shown in the following table. The subscription contains the function apps shown in the following table. The outbound traffic of which app is controlled by using NSG1? - image - image

  1. App4 only
  2. App3 and App4 only
  3. App2, App3, and App4 only
  4. App1, App2, App3, and App4 Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of which Azure App Service tiers support VNET integration; the common trap is assuming Basic/Free tiers cannot use this feature, whereas Premium and Standard tiers can effectively bypass public internet exposure.

This question tests the capability of Azure Functions to integrate with Virtual Networks for secure outbound traffic access. It establishes that all listed function apps, regardless of their specific pricing tier shown in the diagram, can utilize VNET integration to route traffic through subnets protected by NSG1.

Candidates often select 'App4 only' (A) or exclude lower-tier apps, mistakenly believing that only the highest-tier app (App4, likely Premium v3 or Isolated) supports VNET integration, ignoring that Standard/Premium tiers also support it.

Community Discussion (5 comments)

Viggy1212 👍 2 Selected: D
Function apps deployed to a Premium plan can take advantage of virtual network integration for web apps. https://learn.microsoft.com/en-us/azure/azure-functions/functions-premium-plan?tabs=portal The virtual network integration feature: Requires a supported Basic or Standard, Premium, Premium v2, Premium v3, or Elastic Premium App Service pricing tier. https://learn.microsoft.com/en-us/azure/app-service/overview-vnet-integration
HdiaOwner 👍 1 Selected: D
I think Answer is D
ITFranz 👍 1
https://learn.microsoft.com/en-us/azure/app-service/overview-vnet-integration The virtual network integration feature: Requires a supported Basic or Standard, Premium, Premium v2, Premium v3, or Elastic Premium App Service pricing tier. Supports TCP and UDP. Answer = D
ezmoney 👍 1
I'm thinking the answer is D because In this scenario, all the subnets (Subnet1, Subnet2, Subnet3, Subnet4) are associated with the same network security group (NSG1). Am I wrong?
BeginLearningforPP 👍 2
Virtual network integration (VNET) is available in the following Azure App Service plans: Standard: Available for newer App Service deployments Premium: Available for all App Service deployments Basic: Available for newer App Service deployments Premium v2: Available for all App Service deployments Premium v3: Available for all App Service deployments with Isolated plan you can control both Inbound and outbound traffic. Therefore answer is D: App1, App2,App3, and App4

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

All four applications (App1, App2, App3, and App4) are deployed on Azure Functions. Based on standard exam scenarios for AZ-500 involving VNET integration, these apps are configured to use Virtual Network Integration (or Gateway Required for Premium). This feature allows Function Apps running on supported plans (Standard, Premium, Premium v2, Premium v3) to send outbound traffic into a virtual network subnet. Since Subnet1, Subnet2, Subnet3, and Subnet4 are all associated with NSG1, any app integrated into these subnets will have its outbound traffic controlled by NSG1. The community consensus correctly identifies that if the apps are integrated, they all pass through the NSG.

Why the Other Options Are Wrong

Option A (App4 only) assumes only the highest-tier app has VNET capabilities, which is incorrect as other Premium/Standard tiers support it. Option B and C exclude certain apps arbitrarily without evidence that those specific apps lack integration. In Azure security architecture, if an app is integrated into a VNet subnet, its traffic is subject to the NSGs attached to that subnet. Excluding apps implies they are not integrated, but the question context implies a uniform configuration or capability across the environment for testing VNET control.

Community Comment Notes

Community members Viggy1212 and ITFranz referenced Microsoft documentation stating that Virtual Network Integration requires supported Basic or Standard, Premium, Premium v2, Premium v3, or Elastic Premium tiers. As ezmoney noted, "all the subnets... are associated with the same network security group (NSG1)", reinforcing that integration leads to NSG control. The majority voted D, confirming the interpretation that all apps are subject to the network controls via integration.

Official Reference

Exam Strategy

When asked about VNET integration for App Services/Functions, remember that Standard, Premium, and higher tiers support it. If the question implies integration is active, all such apps' traffic is controlled by the NSGs of the target subnets. Do not assume Free/Basic tiers unless explicitly stated as unsupported.

Frequently Asked Questions

Do all Azure Functions tiers support VNET integration?

No. Only Basic, Standard, Premium, Premium v2, Premium v3, and Elastic Premium tiers support Virtual Network Integration. Free and Basic (older) may not.

How does NSG1 affect Function App traffic?

If a Function App uses VNET integration, its outbound traffic enters the specified subnet. NSGs attached to that subnet then filter this traffic.

Related Analysis

← Back to AZ-500 Study Guide