Outbound traffic can be blocked with an NSG that is located on your integration subnet. Here, the inbound rules do not apply as VNet Integration can't be used to support the inbound access to your application. Option A is incorrect. A route table can be placed on the integration subnet to direct/deliver outbound traffic at desired locations. Option B is incorrect. Azure DNS offers name resolution with the help of Microsoft Azure infrastructure and is not a related Azure Networking feature. Option C is incorrect. Traffic Manager is a Load balancing solution. Option D is incorrect. Front Door is also a load balancing solution. Option E is correct. NSGs help in blocking outbound traffic. Reference: https://docs.microsoft.com/en-us/azure/app-service/web-sites-integrate-with- vnet?WT.mc_id=modinfra-33046-thmaure