Based on the exhibit, what should the administrator create so VMs in AppSubnet can access the storage account over a private IP address?
A private endpoint assigns the storage account a private IP address in the VNet, which is exactly what the exhibit requires. With public access disabled, the private endpoint is the correct way for the VMs to reach the storage service privately from AppSubnet.
Why this answer
A private endpoint assigns a private IP address from AppSubnet to the storage account, enabling VMs in that subnet to access the storage account over a private IP within the VNet. This eliminates exposure to the public internet and uses Azure Private Link for secure, direct connectivity.
Exam trap
The trap here is confusing service endpoints (which still use the public endpoint but with source subnet restriction) with private endpoints (which provide a true private IP address), leading candidates to incorrectly choose A when the question explicitly requires access over a private IP address.
Why the other options are wrong
A service endpoint provides access over the Azure backbone network but still uses a public IP address for the storage account, not a private IP address within the virtual network. The question specifically requires private IP access, which only a private endpoint can provide.
When would these options actually be correct?
A service endpoint would be correct if the question asked for secure access from a subnet to a storage account using Azure backbone network without requiring a private IP, or if the goal was to restrict storage account access to a specific subnet while still using the public endpoint.
Why candidates pick the wrong answer
Candidates often confuse service endpoints with private endpoints, thinking both provide private IP connectivity, but service endpoints only route traffic over the Azure backbone while keeping the public endpoint.
Candidates may confuse site-to-site VPN with private connectivity, thinking a VPN tunnel provides private IP access, but it actually extends the network rather than creating a private endpoint within the subnet.