AZ-500 exam dumps

AZ-500 practice question 68 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 68

Select 2

You manage a critical Azure Storage account containing sensitive data. You need to ensure that only specific public IP ranges can connect to the account while still allowing trusted Azure services (such as Azure Backup or Azure Monitor) to access it. Which two actions must you take to meet these requirements?

  1. A

    Set the storage account to allow access from all networks.

  2. B

    Select 'Selected networks' under Firewall and virtual networks, and add your trusted IP addresses.

  3. C

    Enable the 'Allow trusted Microsoft services to access this storage account' option.

  4. D

    Open TCP port 1433 for inbound traffic in the storage account's firewall settings.

  5. E

    Download and apply a custom firewall configuration script from the Azure Marketplace.

Show answer and explanation

Correct answers: B, C

Explanation

When configuring firewall rules on an Azure Storage account, selecting 'Selected networks' ensures only specified IP addresses or subnets can access the resource. Additionally, enabling 'Allow trusted Microsoft services...' allows necessary Azure services to function properly (e.g., Azure Backup, Azure Monitor). Refer to Microsoft Docs (https://docs.microsoft.com/azure/storage/common/storage-network-security) for detailed guidance on configuring firewall settings and network rules.

  • A. Incorrect.

    Option 1 (Incorrect): Choosing 'Allow access from all networks' does not restrict public network access, which would defeat the purpose of limiting connections to specified IP ranges.

  • B. Correct.

    Option 2 (Correct): By selecting 'Selected networks' and specifying IP addresses, you ensure that only those IP addresses can access the storage account, fulfilling the requirement to restrict access to known IP ranges.

  • C. Correct.

    Option 3 (Correct): Enabling 'Allow trusted Microsoft services to access this storage account' ensures services like Azure Monitor and Azure Backup can still communicate with the storage account even though it's behind a firewall.

  • D. Incorrect.

    Option 4 (Incorrect): Azure Storage accounts do not require opening TCP port 1433 (which is commonly associated with SQL Server). Opening this port provides no benefit for storage account firewall rules and is unrelated to the scenario.

  • E. Incorrect.

    Option 5 (Incorrect): There is no requirement to download a custom firewall configuration script from the Marketplace. Azure Portal or PowerShell/CLI configurations are typically sufficient for restricting network traffic.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam