A storage account must be reachable from your virtual network and nowhere else, addressed by a private IP from your own address space so that on-premises staff reach it through the existing VPN. What do you configure?
Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Correct A private endpoint for the storage account
Correct. A private endpoint places a network interface with a private IP from your subnet in front of the service, so it is addressed inside your network, reachable over VPN or ExpressRoute, and its public access can be switched off entirely.
Not correct Keep the public endpoint and add a firewall rule permitting only your virtual network
Wrong for the requirement as stated. Restricting the public endpoint does narrow who may use it, but the resource is still reached at its public name and address — the private IP in your own space is precisely what this does not give you.
Not correct Peer the virtual network with the storage account
Wrong. Peering joins two virtual networks. A storage account is a platform service, not a network, so there is nothing to peer with.
Not correct Deploy the storage account into the subnet the way you would deploy a virtual machine
Wrong. Platform services are not placed into your subnet like a virtual machine; the private endpoint is the mechanism that gives them a presence in it.
Why
Every platform service starts with a public endpoint: a public address and a public name that anyone on the internet can at least attempt to reach, with authentication and firewall rules deciding who succeeds. A private endpoint changes the address itself, projecting the service into your subnet on a private IP so that traffic never needs the internet. A firewall rule changes who may use the public door; a private endpoint installs a different door.
Where this comes from
- Cited
- Microsoft AZ-900 study guide skill area architecture-and-services.compute-and-networking
Practise this
Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.
Practise Microsoft Certified: Azure Fundamentals (AZ-900)
More questions on this objective
- An image-resizing routine runs for about two seconds whenever a file lands in a storage container — perhaps two hundred times on a busy day, and not at all on a quiet one. The team wants to pay for the work done and maintain no servers. Which compute option fits? machine-checked
- A fifteen-year-old accounting application needs a kernel-level driver, a scheduled task that edits the registry, and a runtime version nobody supports any more. The business wants it running in Azure this quarter with as few code changes as possible. Where does it go? machine-checked
- A team runs nine small services, each with its own conflicting library versions. They want each one packaged with its dependencies, starting in seconds, several to a host, without a separate operating system per service. Which compute type are they describing? machine-checked
- Which TWO of these statements about Azure compute types are true? machine-checked
- A public website runs on four identical virtual machines behind a load balancer. Traffic triples while a television advert airs and falls back an hour later. The team wants instances added and removed automatically against CPU, all built from one image, with nobody clicking. Which option is designed for that? machine-checked
- Three virtual machines form a quorum-based cluster in a region that has no availability zones. You want them placed so that neither a single rack losing power nor a single batch of planned host maintenance can take all three at once. What do you configure? machine-checked