AZ-500 exam dumps

AZ-500 practice question 75 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 75

Select 2

You have an Azure Storage account that hosts highly sensitive data. Your company requires that only services and client applications running in a specific Azure Virtual Network (VNet) can access the storage account, and all public traffic must be blocked. Which two actions should you take to implement private access and secure the storage account?

  1. A

    Create an Azure Private Endpoint for the storage account and associate it with a subnet in your target VNet.

  2. B

    Set the routing preference on the storage account to use Microsoft network routing exclusively, thereby disabling the public endpoint automatically.

  3. C

    Disable the AllowBlobPublicAccess property for the storage account to ensure no public traffic can access it.

  4. D

    Configure the storage account’s firewall to Allow access from selected networks and include only your target VNet.

  5. E

    Enable a service endpoint in the VNet for Microsoft.Storage to restrict traffic to Microsoft’s backbone network.

Show answer and explanation

Correct answers: A, D

Explanation

To make Azure Storage accessible only from a specific VNet and block public access, you should create an Azure Private Endpoint and configure the storage firewall to allow traffic only from that VNet. According to Microsoft documentation, Private Link (through a Private Endpoint) ensures traffic remains on the Azure backbone with no public IP exposure. For more information, see the Microsoft docs on 'Private Endpoint for Azure Storage' and 'Configure Azure Storage firewalls and virtual networks.'

  • A. Correct.

    Option 1 is correct. Creating a Private Endpoint for the storage account associates it directly with your VNet through a private IP, preventing traffic from traversing the public internet. This is a primary method of granting truly private access.

  • B. Incorrect.

    Option 2 is incorrect. Choosing Microsoft network routing preference does not completely disable public endpoints; it influences the routing path but does not block direct public access. You still need to configure other settings to ensure no traffic comes from the public internet.

  • C. Incorrect.

    Option 3 is incorrect. Disabling the AllowBlobPublicAccess property helps prevent container-level public access, but it does not prevent all public traffic from reaching the account's endpoints. Additional controls are needed to restrict all public connectivity.

  • D. Correct.

    Option 4 is correct. Configuring the storage account’s firewall to Allow access from selected networks and specifying only the VNet with the Private Endpoint ensures that any attempt to connect over the public internet is denied.

  • E. Incorrect.

    Option 5 is incorrect. Service endpoints improve performance and secure traffic over an Azure backbone but do not eliminate the public endpoint. The storage account can still be reachable publicly unless additional firewall rules or a private endpoint is used.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam