Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 3 question 13 discussion

Actual exam question from Microsoft's AZ-104
Question #: 13
Topic #: 3
[All AZ-104 Questions]

HOTSPOT -
You have several Azure virtual machines on a virtual network named VNet1.
You configure an Azure Storage account as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: never -
The 10.2.9.0/24 subnet is not whitelisted.

Box 2: never -
After you configure firewall and virtual network settings for your storage account, select Allow trusted Microsoft services to access this storage account as an exception to enable Azure Backup service to access the network restricted storage account.

Reference:
https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-windows https://azure.microsoft.com/en-us/blog/azure-backup-now-supports-storage-accounts-secured-with-azure-storage-firewalls-and-virtual-networks/

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 4 months ago
Correct Answer: VNet1’s address space is 10.2.0.0/16. The VNet1 has only 1 Subnet associated: 10.2.0.0/24. The address space of a VNet is irrelevant if there isn’t a corresponding Subnet from, which VMs can be assigned IP addresses. Box1: Never VMs from 10.2.9.0/24 (10.2.9.0 - 10.2.9.255) are out of Subnet. Subnet IP range 10.2.0.0 - 10.2.0. 255.   Box2: Never Since the checkbox to allow trusted Microsoft services is not checked. After you configure firewall and virtual network settings for your storage account, select Allow trusted Microsoft services to access this storage account as an exception to enable Azure Backup service to access the network restricted storage account.
upvoted 410 times
RougePotatoe
1 year, 8 months ago
Their quote "After you configure firewall and virtual network settings for your storage account, select Allow trusted Microsoft services to access this storage account as an exception to enable Azure Backup service to access the network restricted storage account." Section: "Getting started" https://azure.microsoft.com/en-us/blog/azure-backup-now-supports-storage-accounts-secured-with-azure-storage-firewalls-and-virtual-networks/
upvoted 5 times
...
...
Leandroalonso
Highly Voted 3 years, 10 months ago
VMs from the 10.2.9.0/24 should NEVER access the storage!!!!! Since wich the selection of the network is segmented by subnets, and not by virtual networks.
upvoted 76 times
Miles19
3 years, 6 months ago
Yes, that's true. The virtual machine attached to the following virtual network 10.2.9.0/24 will never have access to the storage account, because of the firewall rules, so the correct answer is: -Never -Never
upvoted 19 times
...
besha
3 years, 6 months ago
Technically 10.2.9.0/24 subnet is part of 10.2.0.0/16 subnet which is in the allowed subnet. but should still be Never because it's Endpoint status is not enabled
upvoted 40 times
RamanAgarwal
3 years, 4 months ago
Allowed access is at the subnet level which is 10.2.0.0/24 which includes Ip range 10.2.0.0-10.2.0.255, this means the VM on 10.2.9.0/24 will not have access to storage account.
upvoted 19 times
shnz03
3 years, 3 months ago
I disagree. Your subnet mask understanding for network id and host id is wrong.
upvoted 4 times
shnz03
3 years, 3 months ago
@RamanAgarwal. I apologize. I misread. Your statement is correct.
upvoted 12 times
...
...
...
...
...
SeMo0o0o0o
Most Recent 1 month ago
CORRECT
upvoted 1 times
...
76d5e04
3 months, 4 weeks ago
The question tricks with IP address. The Vnet1 address space 10.2.0.0/16 and the VM address space 10.2.9.0/24 are different. So the VM will never be able to connect
upvoted 1 times
...
ihar_akhremchyk
5 months ago
Incorrect case at all. How did they create subnet "1" with CIDR 10.2.0.0/16 and subnet "Prod" with CIDR 10.2.0.0/24 in one Vnet1? It's impossible to do because of overlapping of the subnets. If you decide to repeat the test case you will receive an error - "Address prefix 10.2.0.0/24 overlaps with the address prefix 10.2.0.0/16 in subnet default. Subnets in the same virtual network cannot overlap."
upvoted 2 times
...
bobothewiseman
6 months, 2 weeks ago
Never Never 10.2.9.0/24 subnet is part of 10.2.0.0/16 subnet which is in the allowed subnet. The reasons it's now allowed is because the Endpoint status is not enabled
upvoted 1 times
bobothewiseman
6 months, 2 weeks ago
correction - *not allowed
upvoted 1 times
...
...
1828b9d
7 months, 1 week ago
This question was in exam 01/03/2024
upvoted 1 times
...
Amir1909
7 months, 1 week ago
Always Never
upvoted 1 times
...
Amir1909
7 months, 1 week ago
Correct Never Never
upvoted 1 times
...
Amir1909
7 months, 1 week ago
- always - always
upvoted 1 times
...
SkyZeroZx
9 months ago
VNet1’s address space is 10.2.0.0/16. The VNet1 has only 1 Subnet associated: 10.2.0.0/24. The address space of a VNet is irrelevant if there isn’t a corresponding Subnet from, which VMs can be assigned IP addresses. Box1: Never VMs from 10.2.9.0/24 (10.2.9.0 - 10.2.9.255) are out of Subnet. Subnet IP range 10.2.0.0 - 10.2.0. 255.   Box2: Never Since the checkbox to allow trusted Microsoft services is not checked. After you configure firewall and virtual network settings for your storage account, select Allow trusted Microsoft services to access this storage account as an exception to enable Azure Backup service to access the network restricted storage account.
upvoted 1 times
...
nandakku
1 year ago
This question appeared in Exam conducted on September 15th - 2023. Answer is, Box 1 -----> Never (Check the CIDR range mentioned. Question contains wrong IP address) Box 2 ------> Checkbox to allow trusted Microsoft services is not checked.
upvoted 3 times
...
Chris1120
1 year, 1 month ago
Never! Never!
upvoted 1 times
...
Madbo
1 year, 5 months ago
It seems that the virtual machines on the 10.2.9.0/24 subnet will have network connectivity to the file shares in the storage account as the subnet "Prod" is enabled with endpoints to access the storage account. Therefore, the answer to the first question should be "always". As for the second question, if the Azure Backup service is configured to access the storage account as an exception, it should be able to back up the unmanaged hard disks of the virtual machines in the storage account. However, if the exception is not configured, the answer should be "never".
upvoted 1 times
...
[Removed]
1 year, 9 months ago
on the test
upvoted 2 times
...
UK7
1 year, 9 months ago
On exam 21st Dec 2022 - answer is correct
upvoted 7 times
...
NaoVaz
2 years ago
1) The virtual machines on the 10.2.9.0/24 subnet will have network connectivity to the file shares in the storage account "never". 2) Azure Backup will be able to back up the unmanaged hard disks of the virtual machines in the storage account "never". Explanation: The range 10.2.9.0/24 is not inside the allowed Virtual networks range "10.2.0.0/24". The option "Allow trusted Microsoft services to access this storage account" is not enabled, so Azure Backup wont be able to back up the disks.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...