You need to restrict access to an Azure AI Language resource so that only a specific virtual network can call the endpoint. Which configuration should you use?
A service endpoint or private endpoint binds the Azure AI Language resource to a specific virtual network, so only traffic from that network reaches the endpoint. This directly enforces the network restriction the scenario requires.
Why this answer
Azure AI Language resources can be isolated to a specific virtual network by enabling either a service endpoint (via the Microsoft.CognitiveServices service tag) or a private endpoint (using Azure Private Link). This configuration ensures that only traffic originating from the designated VNet can reach the resource's endpoint, effectively blocking all public internet access. Service endpoints provide a direct, optimized route from the VNet to the resource, while private endpoints assign a private IP from the VNet to the resource, making it accessible only within the VNet.
Exam trap
The trap here is that candidates often confuse network-level access controls (service/private endpoints) with authentication mechanisms (keys, managed identities) or IP-based firewalls, mistakenly believing that rotating keys or using managed identities can restrict network access, or that a VNet's public IP range is the same as the VNet's internal address space.
How to eliminate wrong answers
Option A is wrong because rotating shared access keys changes the authentication tokens but does not restrict network-level access; any client with the new keys can still call the endpoint from anywhere on the internet. Option C is wrong because assigning a managed identity enables the resource to authenticate to other Azure services (e.g., Azure Key Vault) without storing credentials, but it does not control which networks can reach the resource's endpoint. Option D is wrong because IP firewall rules with the VNet's public IP range are ineffective for restricting access to a specific virtual network, as VNet traffic typically uses private IPs (RFC 1918) and the public IP of a VNet's NAT gateway or load balancer is not the same as the VNet's internal address space; moreover, IP firewall rules cannot distinguish traffic originating from within the VNet versus other sources using the same public IP range.