Microsoft Certified: Azure Administrator AssociateImplement and manage storageHard
An administrator needs to configure an Azure storage account to ensure that all data is accessed exclusively from specific virtual networks within Azure. No public internet access to the storage account should be allowed. Which networking feature should be implemented?
- AService endpoints for Azure Storage
- BAzure Firewall rules
- CNetwork security groups (NSGs)
- DAzure Private Link for Azure Storage
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Private Link for Azure Storage
Azure Private Link for Azure Storage creates a private endpoint in your virtual network for your storage account. This allows traffic to flow over the Azure backbone network, completely bypassing the public internet, and ensures exclusive access from specified virtual networks.
Why the other options are wrong
- A. Service endpoints extend your VNet's identity to Azure services, allowing access over the public backbone but still using public IP addresses and allowing public internet access if not explicitly denied.
- B. Azure Firewall can filter outbound traffic from your VNet, but for inbound access to a storage account, it's not the primary mechanism to enforce private, exclusive access bypassing the public internet.
- C. NSGs filter network traffic to/from Azure resources but cannot prevent public internet access to a public endpoint if rules are misconfigured or if the service itself is public.
Azure Private Link for Storage
Azure Private Link allows you to access Azure PaaS services (like Azure Storage) over a private endpoint in your virtual network, ensuring that traffic between your VNet and the service travels entirely over the Microsoft backbone network.
- Provides a private IP address for the service within your VNet.
- Traffic bypasses the public internet.
- Enhances security and compliance for sensitive data.
Memory trick: Private Link: Secret road to storage.