Microsoft Certified: Azure Administrator AssociateImplement and manage storageHard
An administrator needs to configure an Azure storage account to allow specific Azure virtual machines (VMs) located in a particular virtual network to access its blob containers, while blocking all other network traffic. The solution must be implemented with the least administrative effort and without exposing the storage account to the public internet. Which network access configuration should be applied?
- AConfigure a Service Endpoint for the storage account.
- BGenerate Shared Access Signatures (SAS) for each VM.
- CConfigure a Private Endpoint for the storage account.
- DUse Azure Firewall to filter traffic to the storage account.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure a Private Endpoint for the storage account.
A Private Endpoint creates a private IP address for the storage account within the virtual network, allowing VMs to access it securely over the Azure backbone network without exposure to the public internet. This offers the least administrative effort for granular VM access and maximum security.
Why the other options are wrong
- A. Service Endpoints allow a VNet to access a storage account over the Azure backbone, but the storage account still has a public IP and requires firewall rules to restrict access, which is more administrative effort and less secure than a Private Endpoint.
- B. SAS tokens provide granular access but require per-VM management and are not a network-level access control mechanism for blocking all other traffic.
- D. Azure Firewall can filter traffic, but it's a network appliance that requires more complex setup and management than a Private Endpoint for this specific scenario.
Azure Private Endpoint for Storage
An Azure Private Endpoint provides a private IP address for an Azure service (like Storage Account) inside a virtual network, allowing secure and private access over the Azure backbone network, bypassing the public internet.
- Provides a private IP address for the Azure service.
- Traffic flows over the Azure backbone network, not the public internet.
- Enhances security by eliminating public internet exposure.
- Simplifies network configuration for secure access.
Memory trick: Private Endpoint for ultimate seclusion, Service Endpoint for backbone highway, Firewall for traffic cop.