Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company has an Azure virtual network VNet1 with a subnet named AppSubnet hosting application servers. The applications use an Azure Storage account named contosodata. You must ensure traffic from AppSubnet to contosodata stays on the Microsoft backbone and that the storage firewall blocks internet-originated traffic, with minimal application changes. What should you do first?
Add a user-defined route on AppSubnet that sends all traffic destined for contosodata to the Internet next hop.
Enable the Microsoft.Storage service endpoint for AppSubnet, then add AppSubnet to the storage account's virtual network firewall rules.
Associate an application security group that contains the storage account with AppSubnet.
Create a private endpoint for contosodata in AppSubnet and disable public network access on the storage account.
Virtual network service endpoints extend the identity of a subnet to a supported Azure PaaS service. After you enable the Microsoft.Storage service endpoint on AppSubnet, you can add the subnet to the storage account's firewall rules. Traffic from that subnet then remains on the Microsoft backbone, while the firewall denies requests originating elsewhere. Private endpoints also meet the isolation goal but require new connection strings, so they involve more application changes than service endpoints. User-defined routes and application security groups do not affect how the Storage service is reached over the public internet.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a virtual network service endpoint in Azure?
Open an interactive chat with Bash
What is the difference between a service endpoint and a private endpoint in Azure?
Open an interactive chat with Bash
How does an Azure Storage firewall enhance security?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .