Courseiva
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A storage account has public network access disabled. An application runs on a VM in a VNet and must access the storage account over a private IP address. The team also wants the storage name to resolve to a private address inside the VNet without changing application code. What should the administrator create?

⚠ Common exam trap

Many exam-takers confuse service endpoints with private endpoints, assuming both provide private IP connectivity, when only private endpoints assign a private IP and require a private DNS zone for name resolution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A private endpoint for the storage account and a corresponding private DNS zone link.

A private endpoint assigns the storage account a private IP from the VNet, making it accessible over a private IP address. A corresponding private DNS zone link (e.g., privatelink.blob.core.windows.net) ensures the storage account name resolves to that private IP inside the VNet without modifying application code, meeting both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A service endpoint on the subnet and a storage account firewall rule allowing that subnet.

    Why it's wrong here

    Service endpoints still use the storage account's public endpoint, even though traffic stays on Microsoft's backbone. They do not create a private IP in the VNet, so they do not satisfy the requirement for private address resolution. This option also does not match the disabled public access requirement as cleanly as a private endpoint.

    When this WOULD be correct

    A service endpoint would be correct if the question asked for securing access from a VNet to a storage account without requiring private IP resolution, and the application could use the public endpoint with firewall rules. For example: 'A storage account must be accessible only from a specific VNet subnet, and the application can use the public endpoint.'

  • A private endpoint for the storage account and a corresponding private DNS zone link.

    Why this is correct

    A private endpoint places the storage service on a private IP inside the VNet, and DNS integration allows the storage FQDN to resolve to that private address. That combination meets both requirements: private connectivity and no application code changes. This is the standard pattern when public network access is disabled.

  • An account SAS token with read/write permissions for the application.

    Why it's wrong here

    A SAS token controls authorization, not network path or name resolution. It cannot force traffic to use a private IP address or replace DNS configuration. The problem is network access, so changing the authentication method does not solve it.

    When this WOULD be correct

    An administrator needs to grant a client application time-limited, delegated access to specific storage resources (e.g., blobs or files) without sharing the account key, and the storage account's public network access is enabled. The application can use the SAS token in the connection string or URL.

  • Allow trusted Microsoft services to bypass the storage firewall.

    Why it's wrong here

    Trusted services are useful in certain storage firewall scenarios, but they do not provide a private IP in the VNet or private DNS resolution. They also are not the correct pattern for a VM in a customer VNet that needs private access. The requirement is private endpoint connectivity.

    When this WOULD be correct

    This option would be correct in a scenario where the storage account has public network access disabled, but the application needs to access it from an Azure service (like Azure Backup or Azure Logic Apps) that is listed as a trusted Microsoft service, and the requirement is to allow that service without exposing the storage account to the public internet.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

A private endpoint for the storage account and a corresponding private DNS zone link.Correct answer

Why this is correct

A private endpoint places the storage service on a private IP inside the VNet, and DNS integration allows the storage FQDN to resolve to that private address. That combination meets both requirements: private connectivity and no application code changes. This is the standard pattern when public network access is disabled.

A service endpoint on the subnet and a storage account firewall rule allowing that subnet.Wrong answer — click to see why

Why this is wrong here

Service endpoints do not provide private IP resolution; the storage account's public DNS name still resolves to a public IP. The question requires private IP resolution without changing application code, which only a private endpoint with a private DNS zone can achieve.

★ When this WOULD be the correct answer

A service endpoint would be correct if the question asked for securing access from a VNet to a storage account without requiring private IP resolution, and the application could use the public endpoint with firewall rules. For example: 'A storage account must be accessible only from a specific VNet subnet, and the application can use the public endpoint.'

Why candidates choose this

Candidates often confuse service endpoints with private endpoints, thinking both provide private connectivity. They may overlook the DNS resolution requirement and assume a service endpoint plus firewall rule is sufficient for private access.

An account SAS token with read/write permissions for the application.Wrong answer — click to see why

Why this is wrong here

An account SAS token provides delegated access to the storage account using the public endpoint, but the question requires private IP access and private DNS resolution, which a SAS token cannot achieve.

★ When this WOULD be the correct answer

An administrator needs to grant a client application time-limited, delegated access to specific storage resources (e.g., blobs or files) without sharing the account key, and the storage account's public network access is enabled. The application can use the SAS token in the connection string or URL.

Why candidates choose this

Candidates may think a SAS token is a secure way to grant access without changing the application code, overlooking that it still uses the public endpoint and does not provide private IP connectivity or DNS resolution.

Allow trusted Microsoft services to bypass the storage firewall.Wrong answer — click to see why

Why this is wrong here

Option D allows trusted Microsoft services to bypass the firewall, but it does not provide private IP connectivity or private DNS resolution. The requirement is for the storage account to be accessed over a private IP address and resolve to a private address inside the VNet, which only a private endpoint with private DNS zone can achieve.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the storage account has public network access disabled, but the application needs to access it from an Azure service (like Azure Backup or Azure Logic Apps) that is listed as a trusted Microsoft service, and the requirement is to allow that service without exposing the storage account to the public internet.

Why candidates choose this

Candidates may think that allowing trusted Microsoft services is a simple way to grant access without changing the network architecture, but they overlook the specific need for private IP connectivity and private DNS resolution in this question.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.