exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 5 question 138 discussion

Actual exam question from Microsoft's AZ-104
Question #: 138
Topic #: 5
[All AZ-104 Questions]

HOTSPOT
-

You have an Azure subscription that contains the virtual networks shown in the following table.



The subscription contains the subnets shown in the following table.



The subscription contains the storage accounts shown in the following table.



You create a service endpoint policy named Policy1 in the South Central US Azure region to allow connectivity to all the storage accounts in the subscription.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
conip
Highly Voted 1 year, 6 months ago
I would go for Y N N 1) YES Virtual networks must be in the same region as the service endpoint policy. https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview#limitations 2) NO - By default, if no policies are attached to a subnet with endpoints, you can access all storage accounts in the service as VNET2 is in diff region this policy is definetly not applied to subnet 2 3) NO - Policy allows all storage accounts + IMHO its not full vnet3 to be considered.
upvoted 28 times
ducklaorange
1 year, 5 months ago
I agree, article state if an endpoint is applied but no policy you can access all resources in the endpoint. "Once a policy is configured on that subnet, only the resources specified in the policy can be accessed from compute instances in that subnet. Access to all other storage accounts is denied."
upvoted 3 times
...
...
entee28
Highly Voted 1 year, 6 months ago
Answer is correct Box 1: Y Virtual networks must be in the same region as the service endpoint policy https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview#limitations Box 2: N VNet2 is in SEA Region, so it can only connect to the stoacc in SEA Region through Service Endpoint, which is storage3 Box 3: Y VNet3 is in the South Central US region, and so is the storage2
upvoted 24 times
conip
1 year, 5 months ago
with 3 I would agree to YES if we assume there is only subnet3 there - so the statement should be only storage2 can be accessed from subnet3 (not vnet3 entirely)
upvoted 4 times
amsioso
1 year, 2 months ago
Y, N, Y https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview#limitations
upvoted 1 times
Dankho
4 months, 2 weeks ago
The statement "Only Storage2 can be accessed from VNet3" is False because, under Policy1, all storage accounts (Storage1, Storage2, and Storage3) can be accessed from Subnet3 in VNet3. Even without the policy it's the same because that the behavior of service endpoints enabled on a subnet.
upvoted 2 times
...
...
...
...
Dankho
Most Recent 4 months, 2 weeks ago
Y N N 1) Yes, since the location of Policy1 is South Central US and VNet3/Subnet3 is in that location, you can apply that policy to that Subnet because service endpoint policies can only be applied to the location they were created in. 2) No, because all storage accounts are accessible from VNet2 since it has a Service endpoint there. And similar to #1, the policy wouldn't affect VNet2 either since it's not really restricting anything. 3) No, because the policy allows access from VNet3/Subnet3 to all storage accounts.
upvoted 4 times
...
[Removed]
5 months ago
WRONG Yes No No
upvoted 3 times
...
joolitan
5 months, 1 week ago
- Policy1 can be applied to Subnet3 = Yes (Virtual Network + Service Endpoint must same region = South Central US) - Only storage1 and storage2 can be accessed from VNET2 = No (VNet2 different region) - Only storage2 can be accessed from VNET3 = No (Azure Storage (Microsoft.Storage) Generally available in all Azure regions)
upvoted 2 times
...
joolitan
5 months, 1 week ago
- Policy1 can be applied to Subnet3 = Yes (Virtual Network + Service Endpoint must same region = South Central US) - Only storage1 and storage2 can be accessed from VNET2 = No (VNet2 different region) - Only storage2 can be accessed from VNET2 = No (VNet2 different region)
upvoted 1 times
...
Jo696
5 months, 2 weeks ago
YNN 3) Access to Managed Storage Accounts stopped working after applying a Service Endpoint Policy over the subnet Managed Storage Accounts aren't supported with service endpoint policies. If configured, policies deny access to all Managed Storage Accounts, by default. If your application needs access to Managed Storage Accounts, endpoint policies shouldn't be used for this traffic.
upvoted 1 times
...
dendenp
6 months, 1 week ago
The answer is correct Y,N,Y Please note the policy is applied at subscirption level, so option 3 is Y
upvoted 1 times
...
090200f
8 months, 3 weeks ago
Box 1: Yes subnet3 is in vnet3 which is in south central US region which has policy1 created. Box 2: No it will allow all not only storage 1, 2 Box 3: No policy applicable
upvoted 2 times
...
sairam
10 months ago
1) YES Virtual networks must be in the same region as the service endpoint policy. https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview#limitations 2) NO - By default, if no policies are attached to a subnet with endpoints, you can access all storage accounts in the service as VNET2 is in diff region this policy is definetly not applied to subnet 2 3) NO - According to this link : https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies-overview#limitations When Service Endpoint policies are applied on a subnet, the Azure Storage Service Endpoint scope gets upgraded from regional to global. This process means that all the traffic to Azure Storage is secured over service endpoint thereafter.
upvoted 2 times
...
tashakori
1 year ago
Yes No No
upvoted 1 times
...
AAlmani
1 year ago
Y N N The policy is created, but not mentioned that it get applied!
upvoted 1 times
...
ziggy1117
1 year, 3 months ago
Y - N - N You create a service endpoint policy named Policy1 in the South Central US Azure region to allow connectivity to all the storage accounts in the subscription. Thus all Vnets with the service endpoint can access any storage in the subscription So VNET2 and VNET3 can access storage 1, 2, and 3
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago