exam questions

Exam AZ-900 All Questions

View all questions & answers for the AZ-900 exam

Exam AZ-900 topic 1 question 401 discussion

Actual exam question from Microsoft's AZ-900
Question #: 401
Topic #: 1
[All AZ-900 Questions]

What should you use to prevent traffic from an Azure virtual network from being routed to an Azure Storage account via the internet?

  • A. a network security group (NSG)
  • B. a public endpoint
  • C. Azure VPN Gateway
  • D. a service endpoint
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ciupaz
Highly Voted 2 years, 3 months ago
Selected Answer: A
A is correct, because with the security rules of NSG you can permit /deny traffic inbound /outbound.
upvoted 24 times
...
SilviaS
Highly Voted 1 year, 9 months ago
The only reason that I paid for this subscription was your comments. You are really the added value to this page. For sure it will help me pass the exam. Thank you.
upvoted 16 times
...
Dmarcetic
Most Recent 2 months, 2 weeks ago
Selected Answer: D
zure Virtual Network (VNet) Service Endpoints allow you to securely connect your Azure Virtual Network (VNet) to Azure services (like Storage Accounts, SQL Databases, Key Vault, etc.) over the Azure backbone network, instead of using the public internet.
upvoted 1 times
...
Zakirh
5 months ago
Selected Answer: A
While Network Security Groups (NSGs) control inbound and outbound traffic to and from Azure resources, they do not directly prevent traffic from a virtual network to Azure Storage over the internet. To achieve that, Azure Private Endpoints should be used.
upvoted 4 times
...
Zakirh
5 months ago
Answer should be D. While Network Security Groups (NSGs) control inbound and outbound traffic to and from Azure resources, they do not directly prevent traffic from a virtual network to Azure Storage over the internet. To achieve that, Azure Private Endpoints should be used.
upvoted 1 times
...
gum_hani
6 months, 3 weeks ago
To prevent traffic from an Azure virtual network from being routed to an Azure Storage account via the internet, it is more appropriate to use service endpoints rather than network security groups (NSGs). Service endpoints ensure that the traffic from the virtual network is routed directly to the Azure Storage account through Azure's backbone network, bypassing the internet -By Copilot(Service of MS)
upvoted 1 times
...
pb187
7 months, 1 week ago
I would go "D" It's about "routing" Network Security Groups (NSGs) are used to control inbound and outbound traffic to network interfaces, VMs, and subnets in your virtual network. While NSGs can help secure your Azure environment by allowing or denying traffic based on rules, they don’t specifically prevent traffic from being routed to an Azure Storage account via the internet. To ensure traffic between your virtual network and Azure Storage account stays within the Azure backbone network, you should use private endpoints or service endpoints. NSGs can be used in conjunction with these to further refine and control traffic within your virtual network.
upvoted 2 times
...
Moustafa_Hefaina
7 months, 1 week ago
Selected Answer: D
Answer is Service Endpoint
upvoted 2 times
...
126e81f
8 months, 2 weeks ago
D is correct per chatgpt: To prevent traffic from an Azure Virtual Network (VNet) from being routed to an Azure Storage account via the internet, you should use Virtual Network Service Endpoints or Private Endpoints.
upvoted 3 times
Nathan12345
8 months, 1 week ago
correct
upvoted 1 times
Nathan12345
8 months, 1 week ago
D. a service endpoint
upvoted 1 times
...
...
...
jambroba
9 months, 1 week ago
Selected Answer: D
D. a service endpoint
upvoted 1 times
...
jambroba
9 months, 1 week ago
D. a service endpoint The correct answer to the original question is "D. a service endpoint," as this is the specific solution to ensure that traffic from a VNet to an Azure storage account does not use the public internet. However, NSGs are important tools for general network traffic control and security, and their use is extensively covered in Azure fundamentals.
upvoted 1 times
...
darthhansie
9 months, 1 week ago
Selected Answer: A
This can be achieved by using Private Endpoints or NSG and there is no option for Private Endpoints Private Endpoints are specific to individual resources and provide granular control. Service Endpoints apply to entire services and optimize routing within Azure. Use Azure Network Security Groups (NSGs): Associate NSGs with the subnets within your Azure virtual network. Create security rules within the NSG to block outgoing internet traffic using the service tag Internet. By doing this, you prevent traffic from the virtual network to external internet resources, including Azure Storage accounts.
upvoted 1 times
...
darthhansie
9 months, 1 week ago
Selected Answer: A
In summary, configure network rules for your storage account to restrict access to specific networks or resources, and use NSGs to block internet-bound traffic from your Azure virtual network. This combination ensures secure communication between your virtual network and the storage account while preventing unnecessary exposure to the internet.
upvoted 2 times
...
siculoct
10 months, 2 weeks ago
It's a Server Endpoint
upvoted 1 times
...
jordanmacedo00
1 year, 2 months ago
Selected Answer: D
D is correct "Virtual Network (VNet) service endpoint provides secure and direct connectivity to Azure services over an optimized route over the Azure backbone network. Endpoints allow you to secure your critical Azure service resources to only your virtual networks. Service Endpoints enables private IP addresses in the VNet to reach the endpoint of an Azure service without needing a public IP address on the VNet." https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoints-overview
upvoted 3 times
...
Kee93
1 year, 3 months ago
Filter Azure service traffic with policies, over service endpoints, and filter rest of the Internet or Azure traffic via appliances or Azure Firewall.
upvoted 1 times
...
jesus_exam
1 year, 3 months ago
Correct A. With NSG traffic goes through internet.
upvoted 1 times
jesus_exam
1 year, 3 months ago
Correct D *********
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago