exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 5 question 13 discussion

Actual exam question from Microsoft's AZ-700
Question #: 13
Topic #: 5
[All AZ-700 Questions]

You have an Azure subscription that contains the resources shown in the following table.



You need to ensure that VM1 and VM2 can connect only to storage1. The solution must meet the following requirements:

• Prevent VM1 and VM2 from accessing any other storage accounts
• Ensure that storage1 is accessible from the internet.

What should you use?

  • A. a network security group (NSG)
  • B. a service endpoint policy
  • C. a private link
  • D. a private endpoint
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
roshingrg
Highly Voted 1 year, 5 months ago
B. a service endpoint policy A service endpoint policy can be used to control the access to Azure Storage accounts from virtual networks. By creating a service endpoint policy, you can specify which storage accounts are allowed to be accessed from the virtual network, while blocking access to other storage accounts. In this case, you can create a service endpoint policy that allows access to storage1 and associate it with the virtual network containing VM1 and VM2. This will ensure that VM1 and VM2 can only connect to storage1 and will be prevented from accessing any other storage accounts. Additionally, to ensure that storage1 is accessible from the internet, you can configure the storage account's networking settings to allow public access. This can be done by enabling the appropriate settings such as allowing public access to blobs or enabling a public endpoint. Using a network security group (NSG) would not provide the required granular control over specific storage accounts. A private link or private endpoint would enable private access to the storage account but would not allow access from the internet, which is a requirement in this scenario. Therefore, the best option is to use a service endpoint policy.
upvoted 12 times
...
omgMerrick
Highly Voted 1 year, 8 months ago
Selected Answer: B
Answer appears to be correct. B. a service endpoint policy Virtual Network (VNet) service endpoint policies allow you to filter egress virtual network traffic to Azure Storage accounts over service endpoint, and allow data exfiltration to only specific Azure Storage accounts. Endpoint policies provide granular access control for virtual network traffic to Azure Storage when connecting over service endpoint. Source: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview
upvoted 8 times
...
dblacksmith
Most Recent 2 months, 3 weeks ago
Selected Answer: B
Default By default all traffic goes against the public endpoint of the storage account. Source IP of the traffic is the Public IP of the VM. Service Endpoints Traffic is still directed against the public endpoint of the storage account but the source IP has changed to the private IP of the VM. In fact, the traffic is also using the VNET and Subnet as source in the network dataframe. Private Endpoints The PaaS service now gets a virtual network interface inside the subnet and traffic from the VM to the storage account is now directed against the private IP address.
upvoted 1 times
...
am156
10 months ago
Selected Answer: D
I believe the answer is D - Private Endpoint. Options A (network security group), B (service endpoint policy), and C (private link) are also Azure networking features, but they may not provide the same level of isolation and control over the specific access requirements described in the scenario. Private endpoint is specifically designed to enable private connectivity to Azure services over a private IP address. By using private endpoints for storage1, you can ensure that VM1 and VM2 can connect to storage1 using the private endpoint while preventing them from accessing other storage accounts.
upvoted 4 times
...
Lazylinux
1 year ago
Selected Answer: B
B is Honey For sure B as if NSG is used can only be used with AZ service tags and that will include all storage accounts and cannot differentiate and hence either allow to all storage account or deny all Where as SE policy you can use a resource in SCOPE of SINGLE account in this case 1 storage account or in RG or subscription based then you associate a subnet to the resource in this case the subnet 1 where VMs reside
upvoted 4 times
...
tomtom2022
1 year, 6 months ago
Selected Answer: A
The answer is A. NSG only can filter whether the VMs can access the storage accounts via the service tag, but can't filter which storage account can be accessed.
upvoted 1 times
...
MrBlueSky
1 year, 6 months ago
Selected Answer: A
I believe the answer is A. NSG Storage accounts are accessible from the internet by default so all we need to worry about is restricting the VMs access to all other storage accounts. This is only doable with an NSG from the options listed.
upvoted 1 times
TheBigMan
1 year, 5 months ago
With NSG/service tags you can only limit the region. Like sql.EastUs . Only viable in my opinion B
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago