AZ-500 exam dumps

AZ-500 practice question 83 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 83

Single answer

You have created a Private Link service to provide partner organizations with secure, private connectivity to your custom application hosted behind an internal load balancer in Azure. You must ensure that only specific partner VNets can connect via a private endpoint. Which of the following steps should you take to restrict inbound connections to your Private Link service from only those partner subscriptions?

  1. A

    Manually approve or reject inbound private endpoint connection requests for your Private Link service, authorizing only the partner subscriptions you trust

  2. B

    Enable auto-approval for all subscriptions in your Azure Active Directory tenant so that any new private endpoint requests are automatically granted

  3. C

    Configure a forced-tunneling path from the partner VNets to your on-premises environment to filter incoming traffic to your Private Link service

  4. D

    Attach an Azure Firewall in the partner VNets to block outbound requests from all IP ranges except the IP address of your Private Link service

Show answer and explanation

Correct answer: A

Explanation

To ensure that only authorized partner subscriptions can connect via a private endpoint to a Private Link service, you must approve or reject each private endpoint connection request. This process is the recommended best practice in Azure Private Link deployments as detailed in the Azure documentation (https://learn.microsoft.com/azure/private-link/private-link-service-overview). Enabling auto-approval for all subscriptions may inadvertently grant access to unintended consumers, violating the principle of least privilege.

  • A. Correct.

    Correct: Manually approving inbound private endpoint connection requests enables you to enforce fine-grained control over which partner subscriptions can successfully connect. This approach allows you to reject or remove any unauthorized requests and guarantee only approved partners can access the Private Link service.

  • B. Incorrect.

    Incorrect: Enabling auto-approval for all subscriptions in your tenant will allow any subscription in the directory to connect without explicit authorization. This goes against the requirement to restrict connections to only specific partners.

  • C. Incorrect.

    Incorrect: Forced-tunneling is typically used to direct outbound traffic from Azure to on-premises for inspection or compliance. It does not offer a mechanism to restrict which incoming private endpoints can connect to your Private Link service.

  • D. Incorrect.

    Incorrect: While Azure Firewall can filter outbound traffic from a partner VNet, it does not alone provide gating of inbound private endpoint connections to your Private Link service. You need to manage private endpoint approvals within the Private Link service for that requirement.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam