QuestionQ25
Develop Azure compute solutionsBackground
Overview
You are a developer for Contoso, Ltd. The company runs a social networking website built as a Single Page Application (SPA). The main web application for the social networking site loads user-uploaded content from blob storage.
You are building a solution to monitor uploaded data for inappropriate content. The following process takes place when users upload content by using the SPA:
- Messages are sent to ContentUploadService.
- Content is processed by ContentAnalysisService.
- After processing finishes, the content is posted to the social network, or a rejection message is posted in its place.
The ContentAnalysisService is deployed with Azure Container Instances from a private Azure Container Registry named contosoimages.
The solution will use eight CPU cores.
Microsoft Entra ID
Contoso, Ltd. uses Microsoft Entra ID for both internal and guest accounts.
Requirements
ContentAnalysisService
The company’s data science group built ContentAnalysisService, which accepts user-generated content as a string and returns a probable value for inappropriate content. Any values over a specific threshold must be reviewed by an employee of Contoso, Ltd.
You must create an Azure Function named CheckUserContent to perform the content checks.
Costs
You must minimize costs for all Azure services.
Manual review
To review content, the user must authenticate to the website portion of ContentAnalysisService by using their Microsoft Entra ID credentials. The website is built with React, and all pages and API endpoints require authentication. To review content, a user must be part of a ContentReviewer role. All completed reviews must include the reviewer’s email address for auditing purposes.
High availability
All services must run in multiple regions. Failure of any service in a region must not affect overall application availability.
Monitoring
An alert must be raised if ContentUploadService uses more than 80 percent of available CPU cores.
Security
You have the following security requirements:
- Any web service accessible over the Internet must be protected from cross site scripting attacks.
- All websites and services must use SSL from a valid root certificate authority.
- Azure Storage access keys must only be stored in memory and must be available only to the service.
- All internal services must be accessible only from internal Virtual Networks (VNets).
- All parts of the system must support inbound and outbound traffic restrictions.
- All service calls must be authenticated by using Microsoft Entra ID.
User agreements
When a user submits content, they must agree to a user agreement. The agreement allows employees of Contoso, Ltd. to review content, store cookies on user devices, and track user’s IP addresses.
Information about agreements is used by multiple divisions within Contoso, Ltd.
User responses must not be lost and must be available to all parties regardless of individual service uptime. The volume of agreements is expected to be in the millions per hour.
Validation testing
When a new version of ContentAnalysisService is available, the previous seven days of content must be processed with the new version to verify that the new version does not significantly deviate from the old version.
Issues
Users of ContentUploadService report that they occasionally see HTTP 502 responses on specific pages.
Code
ContentUploadService

ApplicationManifest

You must deploy the CheckUserContent Azure Function. The solution needs to satisfy the security and cost requirements.
Which hosting model should you choose?
Community Discussion