Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You have an Azure SQL Database and a virtual network named VNet1 that is connected to your on-premises network through a site-to-site VPN. You must ensure that:
The database is reachable only through the VPN connection.
No traffic to the database is allowed from the public Internet.
Firewall administration is kept to a minimum.
What should you configure to meet these requirements?
Create a private endpoint for the database in VNet1 and set the database's public network access setting to Disabled.
Configure a user-defined route on VNet1 that forces all Internet-bound traffic through the VPN gateway.
Enable a Microsoft.Sql service endpoint on the VNet1 subnet and add the subnet to the database firewall list.
Deploy the database as an Azure SQL Managed Instance inside a dedicated subnet of VNet1.
A private endpoint places a network interface for the Azure SQL Database inside VNet1, giving the database a private IP address that is reachable across the site-to-site VPN. Disabling public network access removes the public endpoint entirely, eliminating the need to manage Azure SQL firewall rules for Internet traffic. Service endpoints still rely on the public endpoint and cannot be used from on-premises networks. User-defined routes forcing Internet traffic through the VPN do not block the public endpoint itself, and deploying a managed instance changes the deployment model rather than securing the existing database.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a private endpoint in Azure, and how does it work with Azure SQL Database?
Open an interactive chat with Bash
Why are service endpoints insufficient for securing the Azure SQL Database?
Open an interactive chat with Bash
How does disabling public network access for Azure SQL Database improve security?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .