Microsoft Azure Administrator Associate AZ-104 Practice Question
Your organization has an Azure virtual network named VNet1 and an Azure Storage account named Storage1. You need to ensure that resources in VNet1 can access Storage1 without traffic going over the public internet. Additionally, Storage1 must not be accessible from any other networks or the internet. What should you configure to meet these requirements?
Configure firewall rules to allow VNet1's IP address ranges.
Set up a VPN gateway to connect VNet1 to Storage1.
To meet the requirements, you should create a private endpoint for Storage1 in VNet1. This allows resources in VNet1 to securely access Storage1 over the Azure private network. Private endpoints map a specific instance of a PaaS resource to a private IP address in your virtual network, ensuring that the resource is not accessible from the public internet or other networks.
Enabling service endpoints (Option B) allows resources in VNet1 to access Storage1 over the Azure backbone network but does not restrict access from other virtual networks or the internet. Configuring firewall rules (Option C) to allow VNet1's IP ranges would still expose Storage1 to the internet and requires maintaining IP address ranges. Setting up a VPN gateway (Option D) is unnecessary within Azure and more suited for connecting on-premises networks to Azure virtual networks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a private endpoint in Azure?
Open an interactive chat with Bash
What is the difference between private endpoints and service endpoints?
Open an interactive chat with Bash
Why would I want to restrict storage access to only my virtual network?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Configure and manage virtual networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access