Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 3 question 16 discussion

Actual exam question from Microsoft's AZ-104
Question #: 16
Topic #: 3
[All AZ-104 Questions]

You have an Azure subscription that contains a storage account named account1.
You plan to upload the disk files of a virtual machine to account1 from your on-premises network. The on-premises network uses a public IP address space of
131.107.1.0/24.
You plan to use the disk files to provision an Azure virtual machine named VM1. VM1 will be attached to a virtual network named VNet1. VNet1 uses an IP address space of 192.168.0.0/24.
You need to configure account1 to meet the following requirements:
✑ Ensure that you can upload the disk files to account1.
✑ Ensure that you can attach the disks to VM1.
✑ Prevent all other access to account1.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From the Networking blade of account1, select Selected networks.
  • B. From the Networking blade of account1, select Allow trusted Microsoft services to access this storage account.
  • C. From the Networking blade of account1, add the 131.107.1.0/24 IP address range.
  • D. From the Networking blade of account1, add VNet1.
  • E. From the Service endpoints blade of VNet1, add a service endpoint.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
chinnu_07
Highly Voted 2 years, 10 months ago
A,C IS THE CORRECT ANSWER
upvoted 51 times
awssecuritynewbie
2 years, 7 months ago
Option C will allow for the public Address to be added but we just want VM1 to gain access to the VM that can be done via the private IP.
upvoted 4 times
awssecuritynewbie
2 years, 7 months ago
sorry mistake it states from on-perm therefore you need it to allow public OP of the VM to be allowed to access.
upvoted 2 times
...
...
kmaneith
1 year, 11 months ago
correct , attach disk to VM1 has nth to do with firewall
upvoted 2 times
...
holytoni
1 year, 6 months ago
I can confirm that. I tested it myself on the portal. I tried to attach a vhd with my public IP. Only when I am whitelisting my ip i can attach a dsik. I believe the main point here is "Ensure that you can attach the disks to VM1.": In this case "you", means our public IP must be allowed, ergo the onprem net.
upvoted 6 times
...
ggogel
10 months ago
I agree. For clarification: D is not required because the VM does not mount the disk through the REST endpoint. So, network rules do not matter in this case.
upvoted 1 times
...
...
klexams
Highly Voted 2 years, 6 months ago
Too many mixed answers here. Decided to spend hours reading MS Docs! K, let's settle this one once and for all. Technically all answers are correct, however you can only choose 2. So here we go: B, C, D depends on A. And B is selected by default btw (once you do A). E has to be done for the disk to be used by VM1. So the correct answer is A and E. A which will cover B C D. And E as explained above. Hope this helps!
upvoted 38 times
epomatti
2 years, 5 months ago
From someone who did a "lot of research" you clearly have no idea what you're talking about. B is not selected by default with A. You clearly don't understand what "Allow trusted Microsoft services to access this storage account", as this has nothing to do with the question. The question CLEARLY says that you plan do upload from the on-premises network with PUBLIC ip address 131.107.1.0/24. A, C are the only possible combination to answer this question. For other options: - B, theres no need to involve Microsoft trusted services here. - D, that only works if there is a site-to-site VPN, and that is NOT stated in the problem. - E, theres nothing to do with the problem.
upvoted 45 times
klexams
2 years ago
sure you seem to understand everything eh.. NOT! lol. How are you going to attach the disks to the VM1 sweetie???
upvoted 5 times
AzureG0d
1 year, 11 months ago
lmfao!!
upvoted 3 times
...
...
gardenboozer
2 years ago
"Allow trusted Microsoft services to access this storage account" IS selected by default, once you switch to "selected networks" (A). However, trusted Microsoft services don't specifically include Microsoft Compute (VMs), so this answer is not relevant here (see https://learn.microsoft.com/en-us/azure/storage/common/storage-network-security?tabs=azure-portal#trusted-access-for-resources-registered-in-your-subscription)
upvoted 4 times
...
...
...
d7fb451
Most Recent 1 week, 4 days ago
oh, and if the VHD is converted to a managed disk (as it should be), it would not be accessible from the internet.
upvoted 1 times
...
d7fb451
1 week, 4 days ago
if you assume it is using SMB to connect to a file share to "provision" the VM. It could be A,C or A,E. But even then it is missing steps... A,C - need to add the subnet A,E - need to add end point policy
upvoted 1 times
...
SeMo0o0o0o
1 month ago
Selected Answer: AC
WRONG A & C are correct
upvoted 1 times
...
azure_luck
7 months, 3 weeks ago
What if for this type of question i check all answers? Did someone try this?
upvoted 1 times
Rediwed
1 month, 3 weeks ago
You get an error.
upvoted 1 times
...
...
SDiwan
8 months ago
Selected Answer: AC
A: bcoz we need to prevent access from all n/w . Enabling this setting by default enables the setting to allow trusted azure services (option B). C: will create firewall rule to allow on-prem n/w to access the storage account and upload disk. Specifically, option D is not needed bcoz attaching the disk to vm is done by azure resource manager via backbone n/w. So allow trusted services option which is enabled as part of option A is sufficient to attach the disk.
upvoted 4 times
...
bacana
8 months, 3 weeks ago
A and C Allow Azure services on the trusted services list to access this storage account is select by default when you change from "Enabled from all networks" to "Enabled from selected virtual networks and IP addresses"
upvoted 2 times
...
MatAlves
8 months, 3 weeks ago
Configuring access from on-premises networks Go to the storage account that you want to secure. Select Networking. Check that you've chosen to allow access from Selected networks. To grant access to an internet IP range, enter the IP address or address range (in CIDR format) under Firewall > Address Range. To remove an IP network rule, select the delete icon ( ) next to the address range. Select Save to apply your changes.
upvoted 1 times
MatAlves
8 months, 3 weeks ago
https://learn.microsoft.com/en-us/azure/storage/common/storage-network-security?tabs=azure-portal
upvoted 1 times
...
...
nchebbi
10 months, 4 weeks ago
IMHO it should be C&D, before you need do C&D you need for sure to do option A, but here they are asking to actions to meet the requirements, AC or AD alone won't acheive the requirements. Explanations: C is mandatory to have access from on-premises, it should be set in the firewall section D is required to have access to VNet1 to attached the disk to your VM, if you try to add that VNET1 to the Virtual Networks section (if there isn't any service endpoints already created) it will create it. Here's a message I get when I try to add VNET "The following networks don’t have service endpoints enabled for 'Microsoft.Storage.Global'. Enabling access will take up to 15 minutes to complete. After starting this operation, it is safe to leave and return later if you do not wish to wait." So option E is required as well but it will be created automatically when you add the VNet1
upvoted 3 times
...
Ahkhan
10 months, 4 weeks ago
I tested it on 11/12/2023 - A & C are correct. This question could also come in a lab simulation where they will tell you to allow the access to storage account from a specific CIDR.
upvoted 3 times
...
CzechChris
11 months, 1 week ago
I think I decided on every combination at some point, but I agree its AC now. A few people below mentioned that the question is badly written. It would help if C mentioned Add an IP range in the Firewall section, which is what you need to do. As the text underneath Firewall says "Add IP ranges to allow access from the internet or your on-premises networks", which is what you want to achieve. Allow access from the public range so that you can copy up the VM image. https://learn.microsoft.com/en-us/azure/storage/common/storage-network-security?tabs=azure-portal
upvoted 1 times
...
damirbek369
11 months, 2 weeks ago
I go for A,C. D does not make sense. Why would you add a Service Endpoint after enabling Selected Virtual Networks option from Networking of Storage Account if you are not going to add IP Address.
upvoted 1 times
damirbek369
11 months, 2 weeks ago
Sorry, I meant E does not make sense.
upvoted 1 times
...
...
clg003
1 year ago
Selected Answer: AE
A and E... I get how C looks tempting but since you know A best satisfies the limit access req, you now have to figure how to connect it to the VNET and C will not do that. E will connect it to the VNET.
upvoted 2 times
...
iamchoy
1 year ago
Selected Answer: AC
To meet the requirements, you should perform the following actions: A. **From the Networking blade of account1, select Selected networks**. - By default, Azure Storage accounts are accessible from everywhere. Selecting "Selected networks" restricts the access to the specified networks or IP addresses. C. **From the Networking blade of account1, add the 131.107.1.0/24 IP address range**. - This allows you to upload the disk files from your on-premises network with the specified IP address range.
upvoted 4 times
...
GoldenDisciple2
1 year, 1 month ago
When I see this question on the exam, I'm going to close my eyes and click 2 answers. Hopefully I get it right. lol
upvoted 10 times
nmnm22
1 year ago
big same
upvoted 2 times
...
Ahkhan
11 months, 1 week ago
Did you get the question?
upvoted 1 times
...
...
jackill
1 year, 1 month ago
Selected Answer: CD
I vote for C and D. If you look at the Networking configuration of a storage account, after selecting “(x) Enabled from selected virtual networks and IP addresses” option, you see that you can add specific virtual networks and public IP address ranges. So, to “Ensure that you can upload the disk files to account1.” from the on premises network you have to select option “C. From the Networking blade of account1, add the 131.107.1.0/24 IP address range.”. To “Ensure that you can attach the disks to VM1.” you need “D. From the Networking blade of account1, add VNet1.”. Of course, before executing actions C and D you must also execute “A. From the Networking blade of account1, select Selected networks.”. But since you can select only two actions I prefer to select the most relevant ones. The option E is not requested by the question since service endpoint enables private IP addresses in the VNet to reach the endpoint of an Azure service without needing a public IP address on the VNet, which is a good thing to do, but not requested.
upvoted 6 times
Yaruk
1 year, 1 month ago
I selected C & D too...
upvoted 1 times
...
ubiquituz
9 months, 3 weeks ago
D is prolly wrong bcoz activating a service endpoint on vnet1 to storage account will affect the public IP address used by the on-prem vm...endpoints changes every connection to private IP through azure backbone infrastructure...will screw up public IP firewall config https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoints-overview
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...