Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company has an Azure SQL Database named db1 in the East US region. You need to ensure that developers on the corporate network can connect to db1 through the existing site-to-site VPN without exposing the database to the public internet. The solution must use only private IP addressing and minimize changes to routing. What should you configure?
Create a Private Endpoint for db1 in the virtual network that is connected by the VPN, and link a private DNS zone to that network.
Enable a virtual network service endpoint for Microsoft.Sql on the subnet that contains the VPN gateway.
Deploy an Azure Front Door instance with Web Application Firewall in front of db1.
Configure IP firewall rules on db1 to allow the on-premises public IP address space.
A Private Endpoint assigns a private IP address from the connected virtual network to the Azure SQL Database. Traffic to the database remains on the virtual network and can traverse VPN or ExpressRoute private peering without ever using the public endpoint. Linking a private DNS zone allows clients to resolve the database's fully qualified domain name to the private IP automatically.
Service endpoints do not work from on-premises networks because traffic still targets the public endpoint. IP firewall rules still expose the database's public endpoint to the internet. Azure Front Door is a public reverse-proxy service and does not satisfy the private-IP-only requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Private Endpoint in Azure?
Open an interactive chat with Bash
What is a private DNS zone in Azure, and why is it needed?
Open an interactive chat with Bash
Why don’t service endpoints work for on-premises connections?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .