AZ-500 exam dumps

AZ-500 practice question 69 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 69

Select 2

Your organization has an Azure Storage account named contosoProdStorage that hosts sensitive financial data. You must ensure that read and write requests are only allowed from the 10.0.0.0/24 subnet in your VNet and from a known public IP range of 203.0.113.0/24. All other traffic should be blocked. Which two configurations can help you achieve this in the Azure portal? (Choose two).

  1. A
    1. In the Firewalls and virtual networks blade for contosoProdStorage, set 'Allow access from All Networks,' then add 10.0.0.0/24 to the Virtual networks section and 203.0.113.0/24 in the IP rules.
  2. B
    1. In the Firewalls and virtual networks blade for contosoProdStorage, set 'Allow access from selected networks,' add the 10.0.0.0/24 subnet under Virtual networks with a service endpoint, and add 203.0.113.0/24 as an IP rule.
  3. C
    1. Enable the 'Allow trusted Microsoft services to access this storage account' option to permit connections from 203.0.113.0/24.
  4. D
    1. Create a private endpoint for contosoProdStorage in the 10.0.0.0/24 subnet and add 203.0.113.0/24 as an IP rule in the Firewalls and virtual networks blade.
Show answer and explanation

Correct answers: B, D

Explanation

To restrict traffic to specific networks or IP addresses for your Azure Storage account, use the Firewalls and virtual networks blade. 'Allow access from selected networks' combined with service endpoints or a private endpoint ensures only the specified subnets and IP ranges can connect. For more information, refer to the Azure Storage network security documentation: https://learn.microsoft.com/azure/storage/common/storage-network-security.

  • A. Incorrect.

    Option 1: Incorrect. Setting 'Allow access from All Networks' automatically permits traffic from all public endpoints. Even though you add IP rules for 10.0.0.0/24 and 203.0.113.0/24, you cannot block other IP addresses effectively under this setting.

  • B. Correct.

    Option 2: Correct. By selecting 'Allow access from selected networks' and adding both the VNet subnet via a service endpoint and the known public IP range, you restrict access to only these networks while blocking others.

  • C. Incorrect.

    Option 3: Incorrect. 'Allow trusted Microsoft services to access this storage account' enables connections from services like Azure Backup and Azure DevOps, not from arbitrary IP ranges such as 203.0.113.0/24.

  • D. Correct.

    Option 4: Correct. Creating a private endpoint restricts storage account traffic to the chosen VNet subnet. By also specifying 203.0.113.0/24 in the IP rules, you allow that public IP range while denying all others.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam