Courseiva
Implement and Manage Virtual NetworkinghardMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

A storage account must be reachable only from workloads in one Azure subnet. The team wants to keep using the storage account's public FQDN, avoid creating a private IP address in the virtual network, and avoid managing private DNS zones. What should the administrator configure?

⚠ Common exam trap

Candidates often confuse service endpoints with private endpoints, assuming that only private endpoints can restrict access to a single subnet, but service endpoints combined with a storage firewall rule achieve the same goal without private IPs or DNS management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A service endpoint on the subnet and a storage firewall rule for that subnet

A service endpoint on the subnet and a storage firewall rule for that subnet is correct because it allows the storage account to be reachable only from workloads in one Azure subnet while still using the storage account's public FQDN. Service endpoints extend the virtual network identity to the storage account over the Microsoft backbone, and the firewall rule restricts access to that specific subnet. This avoids creating a private IP address in the virtual network and eliminates the need to manage private DNS zones, as the public endpoint is retained.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A private endpoint for the storage account

    Why it's wrong here

    A private endpoint would assign the storage account a private IP address from within your virtual network and typically requires a private DNS zone to resolve the account's endpoint. This introduces additional components and management overhead that the design goal explicitly avoids, whereas a service endpoint keeps the public endpoint and uses the subnet's identity. Therefore it is not the correct approach for simply restricting access to a single subnet.

    When this WOULD be correct

    When the requirement is to access the storage account privately from a VNet without using its public endpoint, and the team is willing to manage private DNS zones or use Azure Private DNS.

  • A service endpoint on the subnet and a storage firewall rule for that subnet

    Why this is correct

    A service endpoint keeps the public endpoint in place while extending the subnet's identity to the storage service. Combined with a storage firewall rule that allows only that subnet, it restricts access without assigning a private IP or requiring private DNS management. This exactly matches the stated design goals.

  • An NSG rule that allows TCP 443 to the storage account

    Why it's wrong here

    A network security group rule that permits TCP 443 to the storage account's public IP only controls traffic flows at the subnet or NIC boundary; it does not interact with the storage account's own firewall. Azure Storage enforces its own allow-list based on source IP addresses or virtual network subnets that have a service endpoint enabled, so an NSG rule alone cannot grant access. In fact, without an appropriate service endpoint and storage firewall rule, traffic allowed by the NSG would still be rejected by the storage platform.

    When this WOULD be correct

    An NSG rule allowing TCP 443 to the storage account would be correct if the goal is to permit outbound traffic from a subnet to the storage account's public endpoint, while other outbound traffic is denied. For example, in a scenario where the storage account is publicly accessible but you need to control which VMs can initiate connections to it, an NSG rule on the subnet would suffice.

  • An application security group tied to the storage account

    Why it's wrong here

    Application security groups are designed to group virtual machines or scale sets by application roles so that network security group rules can reference those groups. They cannot be attached to PaaS resources such as an Azure Storage account, and the storage service does not evaluate ASG membership as part of its network access controls. Consequently, an ASG tied to the storage account would have no effect on reachability.

    When this WOULD be correct

    An administrator needs to allow outbound traffic from a specific set of VMs (grouped in an ASG) to the internet while denying all other outbound traffic. The ASG is referenced in an NSG rule to permit traffic only from those VMs.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

A service endpoint on the subnet and a storage firewall rule for that subnetCorrect answer

Why this is correct

A service endpoint keeps the public endpoint in place while extending the subnet's identity to the storage service. Combined with a storage firewall rule that allows only that subnet, it restricts access without assigning a private IP or requiring private DNS management. This exactly matches the stated design goals.

A private endpoint for the storage accountWrong answer — click to see why

Why this is wrong here

A private endpoint creates a private IP in the VNet and requires managing private DNS zones, which contradicts the requirement to avoid both.

★ When this WOULD be the correct answer

When the requirement is to access the storage account privately from a VNet without using its public endpoint, and the team is willing to manage private DNS zones or use Azure Private DNS.

Why candidates choose this

Candidates may confuse private endpoints with service endpoints, thinking both provide private connectivity, but private endpoints involve more management overhead.

An NSG rule that allows TCP 443 to the storage accountWrong answer — click to see why

Why this is wrong here

NSG rules control traffic at the subnet or NIC level within a virtual network, but they cannot filter traffic to a storage account's public endpoint from outside the subnet. The question requires restricting access to only one subnet, and NSGs alone cannot enforce that the storage account rejects traffic from other sources.

★ When this WOULD be the correct answer

An NSG rule allowing TCP 443 to the storage account would be correct if the goal is to permit outbound traffic from a subnet to the storage account's public endpoint, while other outbound traffic is denied. For example, in a scenario where the storage account is publicly accessible but you need to control which VMs can initiate connections to it, an NSG rule on the subnet would suffice.

Why candidates choose this

Candidates often confuse network security groups with service-level access controls, assuming that an NSG rule can restrict access to a specific Azure service endpoint. They may also think that allowing HTTPS (TCP 443) is sufficient to secure access, overlooking that NSGs do not authenticate or authorize the destination resource.

An application security group tied to the storage accountWrong answer — click to see why

Why this is wrong here

An application security group (ASG) is used to group virtual machines and apply NSG rules based on those groups, not to control access to a storage account. It cannot restrict storage account access to a specific subnet without a private endpoint or service endpoint.

★ When this WOULD be the correct answer

An administrator needs to allow outbound traffic from a specific set of VMs (grouped in an ASG) to the internet while denying all other outbound traffic. The ASG is referenced in an NSG rule to permit traffic only from those VMs.

Why candidates choose this

Candidates may confuse ASGs with network security controls for PaaS services, thinking they can be used to restrict access to storage accounts similarly to how they control VM-to-VM traffic.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A storage account must remain on its public endpoint, but only one Azure subnet named AppSubnet should be allowed to access it from Azure. No private IP is required. Which two actions should the administrator take? Select two.

medium
  • A.Enable the Microsoft.Storage service endpoint on AppSubnet.
  • B.Configure the storage account networking firewall to allow the selected virtual network and subnet.
  • C.Create a private endpoint and disable public network access.
  • D.Link a private DNS zone to AppSubnet.
  • E.Assign the Reader RBAC role to AppSubnet.

Why A: Enabling the Microsoft.Storage service endpoint on AppSubnet allows traffic from that subnet to the storage account over the Azure backbone network, using the public endpoint while restricting access to only that subnet. Option B is correct because configuring the storage account's networking firewall to allow the selected virtual network and subnet explicitly permits traffic from AppSubnet while blocking all other public access, meeting the requirement to keep the public endpoint but limit access to one subnet.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.