Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard
A security team has mandated that all Azure Storage Accounts containing highly sensitive data must only be accessible from a specific Azure Virtual Network (VNet) and from a designated set of on-premises public IP addresses. Any access attempts from outside these approved sources must be blocked. The Storage Account will store blobs and files. Which combination of Azure networking features should be configured on the Storage Account to enforce this policy?
- AAzure Service Endpoints and IP firewall rules on the Storage Account.
- BAzure Firewall with custom rules and a public endpoint for the Storage Account.
- CAzure Private Endpoint and Network Security Groups (NSGs) on the Storage Account.
- DAzure DDoS Protection Standard and private DNS zones for the Storage Account.
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Service Endpoints and IP firewall rules on the Storage Account.
Azure Service Endpoints allow you to secure Azure service resources to your VNet, ensuring traffic from the VNet to the Storage Account stays within the Azure backbone. IP firewall rules on the Storage Account allow you to whitelist specific public IP addresses (like the on-premises ones). Together, these enforce the required access restrictions, blocking all other access.
Why the other options are wrong
- B. Azure Firewall is used to filter traffic for VNets, not directly for securing access to a Storage Account itself. A public endpoint for the Storage Account would still require Service Endpoints/IP rules for granular access.
- C. Private Endpoints provide private connectivity but do not, by themselves, allow for whitelisting specific public IP addresses for on-premises access. NSGs are for VNet resources, not directly for Storage Accounts.
- D. DDoS Protection is for defending against denial-of-service attacks, not for granular access control to a Storage Account. Private DNS zones are for name resolution, not access control.
Storage Account Network Security
Securing an Azure Storage Account by restricting access to specific virtual networks (using Service Endpoints) and/or specific public IP addresses (using IP firewall rules).
- Service Endpoints for VNet access: traffic stays on Azure backbone.
- IP firewall rules for public IP access: whitelisting external sources.
- Default action is to deny all public access unless explicitly allowed.
- Can be combined to create comprehensive access policies.
Memory trick: For Storage, Service Endpoints for VNet, IP Rules for On-Prem.