exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 5 question 55 discussion

Actual exam question from Microsoft's AZ-500
Question #: 55
Topic #: 5
[All AZ-500 Questions]

You have an Azure subscription that contains an Azure SQL Database logic server named SQL1 and an Azure virtual machine named VM1. VM1 uses a private IP address only.

The Firewall and virtual networks settings for SQL1 are shown in the following exhibit.



You need to ensure that VM1 can connect to SQL1. The solution must use the principle of least privilege.

What should you do?

  • A. Set Connection Policy to Proxy.
  • B. Set Allow Azure services and resources to access this server to Yes.
  • C. Add an existing virtual network.
  • D. Create a new firewall rule.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Nick66
Highly Voted 2 years, 3 months ago
Selected Answer: C
The Azure SQL Database firewall allows you to specify IP address ranges from which communications are accepted into SQL Database. This approach is fine for stable IP addresses that are outside the Azure private network. However, virtual machines (VMs) within the Azure private network are configured with dynamic IP addresses. Dynamic IP addresses can change when your VM is restarted and in turn invalidate the IP-based firewall rule. It would be folly to specify a dynamic IP address in a firewall rule, in a production environment. You can work around this limitation by obtaining a static IP address for your VM. For details, see Create a virtual machine with a static public IP address using the Azure portal. However, the static IP approach can become difficult to manage, and it's costly when done at scale. Virtual network rules are easier alternative to establish and to manage access from a specific subnet that contains your VMs.
upvoted 17 times
...
sylarcas
Highly Voted 2 years ago
Selected Answer: C
C is the correct answer. In the answer D. You can add public IPs but in this case VM1 use private ip only.
upvoted 12 times
...
xRiot007
Most Recent 9 months, 1 week ago
You cannot use D to create a firewall rule because VM needs a public IP. The next best thing if D is not possible is C - add an existent VNET...
upvoted 3 times
...
saira23
9 months, 2 weeks ago
In Exam20/07/2024 Answer is C
upvoted 2 times
...
datz
10 months, 2 weeks ago
Selected Answer: C
Cant be D, as per bellow. so C. D. Create a new firewall rule. (Cant be as it clearly says VM only has Private IP no PIP)
upvoted 1 times
...
BMF
1 year, 6 months ago
Selected Answer: C
In exam 4th November
upvoted 1 times
...
TheProfessor
1 year, 6 months ago
Selected Answer: D
D. Create a new firewall rule.
upvoted 2 times
...
BigShot0
1 year, 7 months ago
Selected Answer: D
You should authorize the Machine not the VNET. The question specifically says Least Privilege therefore the VNET may allow many machines to connect.
upvoted 2 times
...
ESAJRR
1 year, 8 months ago
Selected Answer: C
C. Add an existing virtual network.
upvoted 2 times
...
heatfan900
1 year, 8 months ago
Allow Azure services and resources to access this server not enabled, you need to create individual firewall rule entries to add IP addresses. D is right. B does NOT provide LEAST PRIV
upvoted 2 times
Mnguyen0503
1 year, 3 months ago
FW rules only apply to Public IP. VM1 only has Private IP. C is the answer.
upvoted 2 times
...
...
billo79152718
1 year, 11 months ago
Selected Answer: C
C. Add an existing virtual network
upvoted 1 times
...
zellck
2 years ago
Selected Answer: C
C is the answer. https://learn.microsoft.com/en-us/azure/azure-sql/database/network-access-controls-overview?view=azuresql You can also allow private access to the database from virtual networks via: - Virtual network firewall rules: Use this feature to allow traffic from a specific virtual network within the Azure boundary
upvoted 6 times
...
stepman
2 years ago
I forgot what I chose, but this was On exam 4/27 with the new exam experience. No Sim or lab.
upvoted 3 times
...
Potato123Psasas
2 years, 1 month ago
Selected Answer: B
Tested in lab The setting allows connection from VMs. VM is a trusted service for SQL database. When Allow Azure services and resources to access this server is enabled, your server allows communications from all resources inside the Azure boundary, that may or may not be part of your subscription. https://learn.microsoft.com/en-us/azure/azure-sql/database/network-access-controls-overview?view=azuresql
upvoted 3 times
xRiot007
9 months, 1 week ago
B gives TOO MUCH access. You need to allow access only for the VM or the resource in the encompassing scope (which is VNET), not to any resource. Correct answer is C - add an existing VNet (the one with the VM in it)
upvoted 1 times
...
sapthami
2 years ago
B is the correct answer as per the above article.
upvoted 1 times
...
Br1cKd
2 years, 1 month ago
That does not meet the principle of least privilege.
upvoted 7 times
...
...
Manu1986
2 years, 1 month ago
Selected Answer: C
Best idea would be private endpoint, but here we need setting under "Public access" and then select there "Add a virtual network rule" and select your vnet there
upvoted 7 times
...
tutonata
2 years, 1 month ago
Selected Answer: D
FW rule with a singleton IP address representing the VM private IP
upvoted 3 times
pentium75
9 months ago
Can add only public IPs to FW rules
upvoted 1 times
...
...
majstor86
2 years, 2 months ago
Selected Answer: C
C. Add an existing virtual network.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago