AZ-500 exam dumps

AZ-500 practice question 77 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 77

Select 2

You manage an Azure Virtual Network named VNET1 that contains two subnets named SubnetA and SubnetB. You have an Azure Storage account, and you need to restrict its access so that only resources in SubnetA can connect to it through a Service Endpoint, denying all other external traffic. Which two configuration steps should you perform to achieve this requirement? (Choose two.)

  1. A

    Enable the Service Endpoint for Azure Storage on SubnetA and update the Storage account’s firewall to allow only that subnet.

  2. B

    Only configure a private endpoint in SubnetA to restrict traffic to VNET1.

  3. C

    Enable the Service Endpoint for Azure Storage on both SubnetA and SubnetB for redundancy.

  4. D

    Set the Storage account’s public network access to 'Selected networks' and add a virtual network rule for SubnetA.

Show answer and explanation

Correct answers: A, D

Explanation

To secure an Azure Storage account using Service Endpoints, you must enable the endpoint on the specific subnet in your virtual network and then add that subnet to the Storage account’s firewall configuration. By selecting 'Selected networks' in the Storage account’s networking settings and adding a virtual network rule for SubnetA, you ensure only traffic from that subnet has access. Refer to Microsoft documentation (https://docs.microsoft.com/azure/storage/common/storage-network-security#grant-access-from-a-virtual-network) for additional details on configuring service endpoints and restricting access using firewall rules.

  • A. Correct.

    Correct. To use a Service Endpoint, you must enable it on the specific subnet (SubnetA) where you want traffic to originate. After enabling the endpoint, you also configure the Storage account firewall to allow traffic from that subnet.

  • B. Incorrect.

    Incorrect. A private endpoint is a different feature than a Service Endpoint. Private endpoints rely on Azure Private Link, which assigns private IP addresses within the subnet. This does not fulfill the requirement if you specifically plan to use Service Endpoints.

  • C. Incorrect.

    Incorrect. Enabling the Service Endpoint on both subnets contradicts the requirement that only SubnetA can access the Storage account. You should enable it only for SubnetA.

  • D. Correct.

    Correct. When restricting access to a Storage account via Service Endpoints, you typically set the public network access to 'Selected networks' and add a virtual network rule for the subnet. This blocks external traffic from other locations.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam