AZ-700 exam dumps

AZ-700 practice question 234 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 234

Select 2

You are deploying a solution that requires private connectivity between Azure Virtual Machines in a specific virtual network and an Azure Storage account, ensuring no traffic traverses the public internet. You have created a private endpoint for the storage account in a dedicated subnet. Which two additional steps must you take to ensure traffic remains entirely private?

  1. A

    Create and link a private DNS zone to the virtual network for the storage account� subdomain.

  2. B

    Enable a NAT Gateway on the subnet hosting the private endpoint.

  3. C

    Disable public network access on the Azure Storage account.

  4. D

    Assign a service endpoint for the same storage account in the subnet hosting the private endpoint.

Show answer and explanation

Correct answers: A, C

Explanation

When creating a private endpoint for an Azure Storage account, you must ensure DNS resolves to the private IP address instead of the public endpoint and that public network access is disabled. Linking a Private DNS Zone to your virtual network configures name resolution to point to the private endpoint. Disabling public access on the storage account ensures traffic stays private and does not route over the internet. For more information, refer to the Azure documentation on private endpoints and private DNS integration (https://learn.microsoft.com/azure/private-link/private-endpoint-dns).

  • A. Correct.

    Correct. Configuring a private DNS zone (e.g., privatelink.blob.core.windows.net) and linking it to your virtual network ensures that name resolution for the storage account� endpoint points to the private IP address, keeping traffic internal.

  • B. Incorrect.

    Incorrect. While NAT Gateway controls outbound internet traffic for resources in a subnet, it is not required for private endpoint connectivity. A NAT Gateway does not affect the internal DNS resolution or enforce private routing for your storage account.

  • C. Correct.

    Correct. Disabling public network access helps ensure that all traffic to the storage account must use the private endpoint, thereby avoiding the public internet and enhancing security.

  • D. Incorrect.

    Incorrect. A service endpoint is a different feature from private endpoints. You do not combine them on the same subnet to enforce private traffic. Private endpoints alone handle private traffic routing, and service endpoints are not required in this scenario.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam