AZ-700 exam dumps

AZ-700 practice question 249 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 249

Select 2

You manage a subnet within an Azure Virtual Network that has a service endpoint for Azure Storage in the West US region. You need to restrict traffic from that subnet so it can only connect to a specific storage account (mycorporatestorage) in West US, and block access to other storage accounts. Which two configurations are required to achieve this using an Azure service endpoint policy?

  1. A
    1. Create a service endpoint policy definition that specifies the allowed storage account (mycorporatestorage) in the West US region.
  2. B
    1. Associate the service endpoint policy with the target subnet hosting the service endpoint to Azure Storage.
  3. C
    1. Configure a user-defined route (UDR) within the subnet that directs traffic to the storage account� public IP address.
  4. D
    1. Create a private endpoint for the storage account and associate it with the subnet.
Show answer and explanation

Correct answers: A, B

Explanation

Service endpoint policies help you restrict outbound access from a subnet to specific Azure resources when service endpoints are enabled. By creating a policy definition specifying the exact storage account and region, and then associating that policy with the target subnet, only traffic to the defined resource is permitted. This capability is documented in Azure� official documentation on managing service endpoint policies for Azure Storage.

  • A. Correct.

    Option 1 is CORRECT. To enforce access only to a specific storage account, you must create a service endpoint policy definition that includes the exact storage account name (or resource URI) and region. This ensures that traffic from the subnet is allowed only to that specified resource.

  • B. Correct.

    Option 2 is CORRECT. After creating the policy definition, you must associate the service endpoint policy with the subnet where the service endpoint is enabled. Without this association, the policy will not be enforced.

  • C. Incorrect.

    Option 3 is INCORRECT. User-defined routes (UDRs) are not required to restrict traffic to a single storage account with service endpoint policies. UDRs manage IP-based routing, whereas service endpoint policies control access at the service resource level.

  • D. Incorrect.

    Option 4 is INCORRECT. Private endpoints provide a way to connect securely to Azure resources over a private link, but they are not required when using service endpoint policies to control access to a specific storage account. Private endpoints and service endpoints are different approaches.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam