Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard

A security architect is designing the network security for a highly sensitive Azure Storage account that stores critical financial data. The requirement is to ensure that the storage account is only accessible from a specific subnet within a corporate Azure Virtual Network, and absolutely no access should be permitted from the public internet, even if accidentally misconfigured. Which combination of security features provides the strongest network isolation for the storage account?

  1. AService Endpoints with 'Allow trusted Microsoft services' enabled.
  2. BAzure Storage Firewalls and virtual networks with allowed IP ranges.
  3. CPrivate Endpoint for Azure Storage with network policies on the subnet.
  4. DNetwork Security Groups (NSGs) on the storage account's subnet.
Show answer & explanation

Correct answer: C. Private Endpoint for Azure Storage with network policies on the subnet.

A Private Endpoint for Azure Storage creates a private IP address for the storage account within a specific subnet of your virtual network. This makes the storage account available only from within that private network, completely removing it from the public internet. Network policies (such as NSGs) on that subnet can then further restrict which resources within the VNet can access the storage account's private endpoint, providing the strongest possible network isolation and preventing public exposure.

Why the other options are wrong

  • A. Service Endpoints extend your VNet identity to Azure Storage, allowing access only from specified subnets, but the storage account still retains a public IP address (though access is restricted). 'Allow trusted Microsoft services' could also potentially allow broader access than desired.
  • B. Azure Storage Firewalls with allowed IP ranges still relies on public endpoints and can be misconfigured to allow public access. It doesn't offer the same level of private network isolation.
  • D. NSGs alone cannot prevent public internet access to an Azure Storage account if it has a public endpoint. They filter traffic at the network interface/subnet level, but if the storage account is publicly addressable, an NSG on a *different* subnet won't protect it from the internet.

Azure Private Endpoint for Storage

A network interface that connects an Azure Storage account privately and securely to a virtual network, making the storage account accessible only via private IP addresses within that network.

  • Removes storage account from public internet.
  • Provides private IP address within a VNet.
  • Enhances security by eliminating data exfiltration risks.

Memory trick: Private Endpoint is like a secret tunnel for your storage, invisible from the outside.

More Secure data and applications questions