exam questions

Exam AZ-300 All Questions

View all questions & answers for the AZ-300 exam

Exam AZ-300 topic 1 question 26 discussion

Actual exam question from Microsoft's AZ-300
Question #: 26
Topic #: 1
[All AZ-300 Questions]

HOTSPOT -
You have several Azure virtual machines on a virtual network named VNet1.
You configure an Azure Storage account as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: always -
Endpoint status is enabled.

Box 2: Never -
After you configure firewall and virtual network settings for your storage account, select Allow trusted Microsoft services to access this storage account as an exception to enable Azure Backup service to access the network restricted storage account.

Reference:
https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-windows https://azure.microsoft.com/en-us/blog/azure-backup-now-supports-storage-accounts-secured-with-azure-storage-firewalls-and-virtual-networks/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
iselectkane321
Highly Voted 5 years, 7 months ago
BOX 1 wrong?
upvoted 18 times
Cern77
5 years, 7 months ago
You right, only 10.2.0.0/24 is allowed to access this storage account ... 10.2.9.0/24 is not in 10.2.0.0/24 !
upvoted 52 times
Rafael1984
5 years, 4 months ago
endpoint is enable, Box 1 is right.
upvoted 2 times
Fred_Freedom
5 years, 4 months ago
@Rafael1984 The endpoint is enable though, it is enable to 10.2.0.0/24, but not to 10.2.9.0/24. So, the endpoint is not enable to 10.2.9.0/24. So, I think that the correct answer for BOX 1 is "never", but not "always".
upvoted 23 times
tartar
4 years, 9 months ago
I hope it's not a typo.. Never, Never.
upvoted 1 times
...
...
...
OsimIndia
4 years, 6 months ago
So Box1 should be Never...
upvoted 1 times
...
...
...
sami777
Highly Voted 5 years, 4 months ago
So after reading onlyfunmails comments answer will be both box = never.
upvoted 14 times
SIDNEY1
5 years, 1 month ago
Agreed, the 10.2.9.0/24 is part of the first subnet listed in the exhibit. The endpoint status is not enabled. So box 1 is Never. Box 2 is Never too, the trusted MS services checkbox is unchecked.
upvoted 13 times
...
...
umair686
Most Recent 4 years, 5 months ago
https://www.exam-answer.com/microsoft/az-104/question34
upvoted 1 times
...
azurecert2021
4 years, 5 months ago
The CORRECT selection is NEVER, NEVER and here is why. since 10.2.9.0/24 part of 10.2.0.0/16 is not checked and 10.2.0.0/24 is allowed to access this storage account where 10.2.9.0/24 is not in 10.2.0.0/24 ! ,The endpoint is enable though, it is enable to 10.2.0.0/24, but not to 10.2.9.0/24. So, the endpoint is not enable to 10.2.9.0/24. A subnet mask of 24 bits basically means that the first 3 numbers of the IP are FIXED! Thus, the 10.2.0 will never change and the remaining number gives 256 subnet addresses. Then, an IP starting by 10.2.9 does not belong to the subnet that is allowed. For fun try it on the portal, when configuring this option it forces you to select subnets, which means that, in order to provide access, they should be explicitly shown on the configuration screen.
upvoted 1 times
...
MMohammad
4 years, 9 months ago
The correct answer is: Never, Never
upvoted 3 times
djolenole
4 years, 6 months ago
Correct(never,never), 10.2.9.0/24 is different subnet and must be specified!
upvoted 1 times
...
...
a_Ri
4 years, 9 months ago
10.2.9.0/24 is not in the allowed subnet list. the first one = never
upvoted 1 times
...
ercank
4 years, 10 months ago
Never, Never. You enable Service Endpoint at Subnet Level and 10.2.9.0/24 is at another Subnet.
upvoted 3 times
...
rvegmen
4 years, 10 months ago
I think the answer is correct. The firewall configuration is limiting the access to that specific VNet. The service endpoint in prod subnet is changing the routing via MS internal backbone rather than going outside, but that does not define the access, just where the traffic is routed.
upvoted 1 times
...
jw_duke
4 years, 11 months ago
I think given ans is correct based on the provided IP subnets: first subnet : 10.2.0.0/16 which covers 10.2.9.0/24 subnets. also with Service Endpoint enabled. that will bypass the firewall.
upvoted 1 times
Remco
4 years, 11 months ago
There is no subnet 10.2.0.0/16. The VNET address space is 10.2.0.0/16, containing one subnet 10.2.9.0/24 (if the screenshot is correct)
upvoted 3 times
...
...
Harkonnen
4 years, 11 months ago
Regarding the Endpoint, just look at https://azure.microsoft.com/en-in/blog/virtual-network-service-endpoints-and-firewalls-for-azure-storage-now-generally-available/ and realise how the arrow departs from the subnet towards the storage account. Therefore, connection is allowed on a subnet basis and 10.2.9 is not a subnet that is allowed.
upvoted 1 times
...
Harkonnen
4 years, 11 months ago
The CORRECT selection is NEVER, NEVER and here is why. A subnet mask of 24 bits basically means that the first 3 numbers of the IP are FIXED! Thus, the 10.2.0 will never change and the remaining number gives 256 subnet addresses. Then, an IP starting by 10.2.9 does not belong to the subnet that is allowed. For fun try it on the portal, when configuring this option it forces you to select subnets, which means that, in order to provide access, they should be explicitly shown on the configuration screen.
upvoted 3 times
...
Ausias18
4 years, 11 months ago
This question appeared in my AZ-104 exam
upvoted 1 times
...
gboyega
4 years, 11 months ago
NEVER NEVER
upvoted 7 times
...
BiggusJiggus
4 years, 11 months ago
I had this very question in an exam (AZ104) - looks like a typo, but the wording is so ambiguous its impossible to tell....
upvoted 1 times
...
DeveshSolanki
4 years, 11 months ago
Both option is NEVER
upvoted 1 times
...
tanito83
5 years ago
Te correct answer is: Never, Never. Please, modify it.
upvoted 1 times
...
Chokies
5 years ago
If you lab it address range for the vnet will not actually appear. It is never never because not until you add service end point to the subnet or add new subnet to the network and firewall settings of the storage it will not be enable.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...