exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 7 question 2 discussion

Actual exam question from Microsoft's AZ-700
Question #: 2
Topic #: 7
[All AZ-700 Questions]

You need to provide access to storage2. The solution must meet the PaaS networking requirements and the business requirements.
Which connectivity method should you use?

  • A. a private endpoint
  • B. Azure Firewall
  • C. Azure Front Door
  • D. a service endpoint
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wsrudmen
Highly Voted 2 years, 11 months ago
Selected Answer: A
Azure Service Endpoint provides secure and direct connectivity to Azure PaaS services over an optimized route over the Azure backbone network. Traffic still left your VNet and hit the public endpoint of PaaS service. ==> Then it can't meet the goal because of the public IP Azure Private Link (or Private Endpoint) allows you to access Azure PaaS services over Private IP address within the VNet. It's then OK A is the answer
upvoted 31 times
Breadfan
8 months, 4 weeks ago
Answer is D a service Endpoint. If you only need a secure connection between the virtual network and another resource, you should use a service endpoint, which means your resources will still have public exposure and you will be accessing those resources using the public endpoint of the resource. However, if you need to access your azure resources from on-premises through an Azure gateway, a regionally peered virtual network, or a globally peered virtual network, use a private endpoint. The private endpoint will allow connection using the private IP of the resources, eliminating the public exposure completely.
upvoted 1 times
Breadfan
8 months, 4 weeks ago
https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/service-endpoints-vs-private-endpoints/ba-p/3962134
upvoted 1 times
...
...
siddique12345
1 year, 5 months ago
According to this link, service point is the answer: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoints-overview#key-benefits Service endpoints enable securing of Azure service resources to your virtual network by extending VNet identity to the service. Once you enable service endpoints in your virtual network, you can add a virtual network rule to secure the Azure service resources to your virtual network. The rule addition provides improved security by fully removing public internet access to resources and allowing traffic only from your virtual network.
upvoted 3 times
...
jeffangel28
2 years, 8 months ago
Perfectly explained!
upvoted 1 times
...
erima21
2 years, 7 months ago
Correct! - Service endpoints does not remove public endpoint. - Private endpoints remove public access.
upvoted 9 times
...
...
Payday123
Highly Voted 2 years, 10 months ago
Selected Answer: D
"Virtual Network (VNet) service endpoint provides secure and direct connectivity to Azure services over an optimized route over the Azure backbone network. Endpoints allow you to secure your critical Azure service resources to only your virtual networks. Service Endpoints enables private IP addresses in the VNet to reach the endpoint of an Azure service without needing a public IP address on the VNet." And it is cheaper
upvoted 15 times
...
bobothewiseman
Most Recent 3 months ago
Selected Answer: D
Service endpoints allow you to connect directly to Azure services (like storage accounts) from specific VNets. They extend your virtual network’s private IP space to Azure storage, ensuring access from VNet2 and VNet3 but preventing exposure of the public endpoint. • You cannot use a private endpoint here because it is designed for specific resource access (like databases), and service endpoints are the preferred choice for storage.
upvoted 1 times
...
manny72
8 months, 2 weeks ago
Selected Answer: D
The whole reason why service endpoints are there is to provide secure access from Azure subnets to supported services like storage accounts. If you don't use a SE in this case, then when? It has no cost compared to a private endpoint and you can select the subnets to give access to and block the others and the public access. The way it works is that it uses public IP but instead of the route being directed through the internet, it goes through the Microsoft backbone network. So even with public access blocked, it's still reachable from selected networks.
upvoted 2 times
...
Steveandlewis
12 months ago
To provide access to storage2 while meeting the PaaS networking requirements and the business requirements, you should use Private Endpoint. Private Endpoint allows a network interface with a private IP address to be created in your Azure Virtual Network (VNet). The private IP address provides secure and direct connectivity to your PaaS service, in this case storage2, over a private link. This ensures that the data between your VNet and storage2 traverses over the Microsoft backbone network, eliminating exposure to the public internet. This method aligns with the business requirement of minimizing costs as it does not require any additional outbound data transfer costs that are associated with other methods like service endpoints. It also satisfies the PaaS networking requirement of making storage2 accessible from Vnet2 and Vnet3 without exposing the public endpoint of storage2. Remember to set up the necessary DNS configurations for Private Endpoint to ensure that the requests to storage2 are routed through the private endpoint.
upvoted 1 times
...
cerifyme85
1 year, 2 months ago
Selected Answer: D
Service endpoint is free -- Business req --> minimise cost https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/service-endpoints-vs-private-endpoints/ba-p/3962134#:~:text=Cost,free%20of%20use)
upvoted 4 times
cerifyme85
1 year, 1 month ago
Sorry was wrong A PEP --> Removes public access totallt SEP --> Connection still made to Public endpoint .. privately
upvoted 2 times
...
...
c2e9cb4
1 year, 3 months ago
Selected Answer: D
i validate reponse D for low cost and fiting requiremnet
upvoted 2 times
...
Rododendron2
1 year, 4 months ago
Selected Answer: D
D - requirements met & better cost. As well, there shall not be access from on premises - additional work to filter
upvoted 2 times
...
GBAU
1 year, 6 months ago
This question is likely EOL given: https://learn.microsoft.com/en-us/azure/expressroute/about-fastpath Virtual network (VNet) Peering FastPath sends traffic directly to any VM deployed in a virtual network peered to the one connected to ExpressRoute, bypassing the ExpressRoute virtual network gateway. This feature is available for both IPv4 and IPv6 connectivity. So with FastPath to Vnet1, it sends traffic directly to Vnet2 and Vnet3 as well (both being peered). I take this to mean no new connections for the circuit needed, and no need for a gateway transit in the peering.
upvoted 1 times
GBAU
1 year, 6 months ago
How did this end up in this one, it was meant for the other version of the question, doh!
upvoted 2 times
...
...
derp12352
1 year, 8 months ago
It doesn't matter if a service endpoint uses the public IP. You can still use it without EXPOSING it (the requirement listed). You would just have public access disabled.
upvoted 5 times
...
JennyHuang36
2 years, 2 months ago
In exam Feb, 2023
upvoted 4 times
...
energie
2 years, 2 months ago
Selected Answer: A
"Virtual Network (VNet) Service Endpoint provides secure and direct connectivity to (native)Azure services"(NOT the private services provisioned by you). Private Endpoint brings the private services provisioned by you(like Azure Storage, Azure SQL Database etc.) to the VNet.
upvoted 1 times
...
staffo
2 years, 2 months ago
Both answers are technically correct (As the public ip is already blocked) except when it comes to costs. Service Endpoints are free and private endpoints include additional costs. So to minimise costs use Service Endpoints.
upvoted 5 times
...
TJ001
2 years, 3 months ago
Service end point still connect to public IP of the storage account ...The question should have been better phrased to have proper use case for service endpoint..I
upvoted 2 times
...
chatlisi
2 years, 3 months ago
Selected Answer: D
Storage 1 can be accessed from on prem via Private Endpoint only (Service Endpoint does not support on prem access) Storage 2 should be via Service Endpoint since the communication is within Azure only.
upvoted 7 times
...
jellybiscuit
2 years, 6 months ago
Selected Answer: A
A - private endpoint - a service endpoint does not remove the public endpoint. The storage account could be accessed both through the service endpoint and publicly. I have a hard time imagining that service endpoint is the correct answer to any question that would appear on the test today.
upvoted 1 times
...
[Removed]
2 years, 7 months ago
Selected Answer: D
D is correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago