AZ-700 exam dumps

AZ-700 practice question 228 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 228

Single answer

You are implementing Azure Front Door to serve traffic for a static website hosted in an Azure Storage account. Due to strict security requirements, you must ensure all traffic from Azure Front Door to the storage origin flows over a private channel, and the storage account is not accessible via the public internet. Which configuration step is required to achieve this?

  1. A

    Create a private endpoint for the storage account, disable public network access on the storage account, and configure the Azure Front Door origin to use the private endpoint� hostname.

  2. B

    Enable service endpoints for the storage account and configure the storage account firewall to allow traffic only from Front Door IP ranges.

  3. C

    Associate Azure Front Door with the storage account� public endpoint while enabling a Web Application Firewall (WAF) policy to limit inbound connections.

  4. D

    Deploy an Azure Private Link service in your Azure Front Door resource group and link it directly to the storage account� public endpoint.

Show answer and explanation

Correct answer: A

Explanation

When securing an origin with Private Link in Azure Front Door, you must create a private endpoint on the origin (e.g., storage account) side and restrict public network access. Then, configure Azure Front Door� origin settings to use that private endpoint hostname. This setup ensures that traffic flows privately and prevents direct internet exposure to the storage account. For more details, consult the official Azure documentation on 'Using Private Link with Azure Front Door' and 'Restrict network access to PaaS resources'.

  • A. Correct.

    Correct. Creating a private endpoint for the storage account and disabling its public access ensures that external requests cannot reach the storage account directly. Configuring Azure Front Door to use the private endpoint� hostname forces all traffic to flow over the private link, meeting the strict security requirements.

  • B. Incorrect.

    Incorrect. Service endpoints still require access over a publicly routable IP, and the storage account would remain reachable via the internet if properly guessed/allowed. This does not provide the full isolation that a private endpoint with disabled public access does.

  • C. Incorrect.

    Incorrect. By associating Azure Front Door with the public endpoint, you do not block direct public access to the storage account. A WAF policy may restrict or filter traffic but does not eliminate the public endpoint exposure.

  • D. Incorrect.

    Incorrect. Azure Private Link in Azure Front Door requires creating a private endpoint on the origin side (e.g., the storage account). You cannot deploy the Private Link service in Azure Front Door itself; the correct approach is to tie Front Door to a private endpoint on the origin to secure traffic.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam