A security architect is designing a solution for a financial services company that needs to prevent data exfiltration from Azure PaaS services such as Azure SQL and Azure Storage. Which feature enforces that traffic to these services only flows through the customer's virtual network?
-
A
Private Link and Private Endpoints
-
B
Service Tags on NSGs
-
C
Azure Firewall FQDN filtering
-
D
VNet Service Endpoints with NSG rules