AZ-700 exam dumps

AZ-700 practice question 246 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 246

Single answer

You have an Azure virtual network (VNet) hosting application servers in the same region as your Azure Storage account. You want to ensure traffic from these servers to your storage account remains on the Azure backbone, restricted so that only requests originating from your VNet are accepted. You also want to avoid setting up custom DNS entries or creating private IP addresses for the storage resource. Which networking configuration should you use?

  1. A

    Enable storage firewall rules with specific public IP addresses

  2. B

    Configure a service endpoint for the Azure Storage account

  3. C

    Deploy a private endpoint for the Azure Storage account

  4. D

    Set up forced tunneling to the storage account through a Network Virtual Appliance (NVA)

Show answer and explanation

Correct answer: B

Explanation

Service endpoints allow you to secure your Azure services by restricting traffic to a virtual network while keeping that traffic on the Azure backbone. This meets the scenario� requirements�no extra DNS setup, no private IP creation, and traffic restricted to your VNet. For more information, refer to 'Virtual network service endpoints overview' in Microsoft Azure documentation.

  • A. Incorrect.

    Option 1: Incorrect. While you can restrict storage account access by IP allow listing, the traffic still travels over the public internet, which does not meet your requirement of keeping traffic on the Azure backbone. You also have to manage the IP addresses.

  • B. Correct.

    Option 2: Correct. A service endpoint ensures that traffic from your VNet to Azure Storage stays on the Azure backbone, and you can restrict the storage account to accept traffic only from your VNet, without needing private IP addresses or custom DNS configurations.

  • C. Incorrect.

    Option 3: Incorrect. A private endpoint would also secure traffic, but it requires creating a private IP address in your VNet and usually involves configuring a dedicated private DNS zone. The question explicitly states that you do not want to create private IP addresses for the storage resource.

  • D. Incorrect.

    Option 4: Incorrect. Forced tunneling can route traffic through an NVA or on-premises environment, but it does not intrinsically restrict access at the service level and is more complex to set up. This does not straightforwardly fulfill the requirement to simplify configuration and limit traffic to your VNet.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam