Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You have an Azure Storage account named contososa and create a private endpoint for it in VNET1. Virtual machines in VNET1 resolve contososa.blob.core.windows.net to the private IP, but on-premises servers connected through a site-to-site VPN still receive the public IP. You must ensure on-premises servers use the private endpoint without changing connection strings. What should you do?
Add an A record for contososa.blob.core.windows.net in the on-premises DNS zone that points to the private IP address.
Disable public network access on the storage account.
Enable an Azure Storage service endpoint on the VPN gateway subnet.
Configure the on-premises DNS servers to forward the zone privatelink.blob.core.windows.net to a DNS forwarder hosted in VNET1.
The on-premises DNS servers must resolve the storage account's FQDN to the private IP that Azure assigned to the private endpoint. The recommended approach is to create a conditional forwarder that sends all queries for the privatelink.blob.core.windows.net zone to a DNS forwarder (for example, Azure DNS Private Resolver or a custom DNS server) located inside VNET1, where the private DNS zone is linked. This causes on-premises queries for contososa.blob.core.windows.net to be answered with the private IP.
Adding a static A record on-premises is not advised because the private IP can change if the endpoint is recreated. Disabling public network access does not fix DNS resolution; the name would still resolve to the public IP and connectivity would fail. Service endpoints are unrelated to private endpoints and do not influence DNS behavior.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is a DNS forwarder used instead of a static A record?
Open an interactive chat with Bash
What is the privatelink.blob.core.windows.net DNS zone?
Open an interactive chat with Bash
What is the Azure DNS Private Resolver and how does it help here?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .