Microsoft Azure Security Engineer Associate AZ-500 Practice Question

VNet1 in East US contains a subnet named AppSubnet where VMs upload data to several Azure Storage accounts. You must make sure that traffic from AppSubnet to the storage accounts travels across the Microsoft backbone, and that the storage accounts can be configured to reject connections not coming from AppSubnet. You cannot assign private IPs to the storage accounts or change their DNS. Which feature should you enable on AppSubnet?

  • Enable a virtual network service endpoint for Microsoft.Storage on AppSubnet.

  • Associate a NAT gateway with AppSubnet to provide a static outbound IP.

  • Create a private endpoint for each storage account and link a private DNS zone.

  • Deploy an Azure Firewall and configure DNAT rules to forward storage traffic.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot