mediummultiple choiceObjective-mapped

A storage account must be reachable only from a single Azure VNet. The team wants the storage account to have a private IP in that VNet and wants to disable public network access. Which solution should the administrator implement?

Question 1mediummultiple choice
Full question →

A storage account must be reachable only from a single Azure VNet. The team wants the storage account to have a private IP in that VNet and wants to disable public network access. Which solution should the administrator implement?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Configure a service endpoint on the subnet and keep public network access enabled.

Service endpoints do not give the storage account a private IP address. They also do not meet the requirement to remove public access.

B

Best answer

Create a private endpoint for the storage account and disable public network access.

A private endpoint places a private IP address in the VNet for the storage service, allowing traffic to stay on the private network path. Disabling public network access ensures the service cannot be reached through its public endpoint.

C

Distractor review

Assign a shared access signature and rely on IP-based firewall rules.

A SAS controls authorization, not private network placement. IP firewall rules still depend on the public endpoint and do not create a private IP in the VNet.

D

Distractor review

Use a route table to force traffic to the storage account over the virtual network gateway.

Route tables cannot turn a PaaS service into a private endpoint. They also do not provide the private IP mapping the team needs.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: Create a private endpoint for the storage account and disable public network access. — A private endpoint is the correct choice when a PaaS service must appear as a private IP inside a VNet. This allows traffic to use private addressing and avoids exposure through the public endpoint. Disabling public network access adds another layer of control by ensuring only private connectivity is accepted. In Azure, this is the standard pattern for reducing exposure of storage and other supported services. Why others are wrong: Service endpoints extend subnet identity to the service but do not create a private IP, so they do not satisfy the requirement. SAS tokens authorize access but do not change the network path. Route tables cannot convert a storage account into a private resource or replace the private endpoint architecture.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.