AZ-104 exam dumps

AZ-104 practice question 60 of 289

Microsoft Certified: Azure Administrator Associate. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-104 Question 60

Single answer

You manage an Azure Storage account named contosodata, which is currently accessible from all networks. A new security policy requires that only resources within a subnet named AppSubnet of an Azure Virtual Network (VNet) named CorpVNet be allowed to connect to contosodata. Which configuration change should you make to meet this requirement?

  1. A

    Configure the Firewall and virtual networks setting to Selected networks, add CorpVNet with the AppSubnet, and enable service endpoints for Azure Storage on AppSubnet.

  2. B

    Create a private endpoint for contosodata in the AppSubnet, and set public network access for the storage account to Disabled.

  3. C

    Enable the Allow trusted Microsoft services to access this storage account option under Firewalls and virtual networks.

  4. D

    Retain the Allow all networks setting in Firewalls and virtual networks, and apply an inbound deny rule in a network security group (NSG) for all other subnets.

Show answer and explanation

Correct answer: A

Explanation

To restrict an Azure Storage account to a single subnet, you must configure the storage firewall to ‘Selected networks’ and define the specific virtual network and subnet where access is permitted. By enabling a service endpoint for Azure Storage on that subnet, traffic is routed securely to the storage account without exposing it to the public internet.

  • A. Correct.

    This option correctly restricts access to CorpVNet’s AppSubnet by selecting ‘Selected networks’ for the storage account, adding the specific VNet and subnet, and enabling a service endpoint. This ensures that only traffic from AppSubnet can reach the storage account.

  • B. Incorrect.

    While creating a private endpoint in AppSubnet and disabling the public endpoint can also restrict access, this method imposes additional complexity (e.g., private DNS integration) and might not be necessary if your requirement focuses on using existing service endpoints.

  • C. Incorrect.

    Enabling 'Allow trusted Microsoft services' only grants access to certain Azure services, not your subnet’s resources. It does not inherently restrict external traffic and does not meet the specific requirement.

  • D. Incorrect.

    Leaving the storage account open to 'Allow all networks' does not meet the requirement of restricting traffic solely to a specific subnet. Configuring an NSG alone does not prevent public inbound access at the storage account level.

Timed practice exam

Take a AZ-104 practice test under exam conditions

60 questions in 60 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam