AZ-104 Implement and Manage Storage Practice Question
An application runs in a subnet and must reach a storage account over the public endpoint, but only that subnet should be allowed. The team does not want to use a private endpoint. Which two configurations should the administrator use? Select two.
⚠ Common exam trap
Test-takers frequently confuse service endpoints with private endpoints, assuming private endpoints are required for subnet-specific access, but service endpoints plus virtual network rules achieve the same restriction on the public endpoint without the cost or complexity of private endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft.Storage service endpoint on the subnet.
Enabling the Microsoft.Storage service endpoint on the subnet (A) ensures that traffic from the subnet to the storage account's public endpoint is routed through the Azure backbone network and uses the source IP of the subnet's virtual network, allowing the storage account firewall to identify the traffic. Adding the subnet to the storage account's virtual network rules (B) then explicitly permits only that subnet's traffic, denying all other public endpoint access. Together, these two configurations restrict access to the storage account's public endpoint exclusively to the specified subnet without requiring a private endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Microsoft.Storage service endpoint on the subnet.
Why this is correct
Enabling a Microsoft.Storage service endpoint extends the identity of the subnet to the storage service, so storage accounts can permit access based on the subnet's virtual network address space rather than a specific private IP. This flag must be set on the subnet itself before a virtual network rule can be added to the storage account. Because the endpoint uses the public endpoint of the storage service, no private IP address is allocated, which matches the scenario's constraint.
- ✓
Add the subnet to the storage account's virtual network rules.
Why this is correct
Adding the subnet to the storage account's virtual network rules is the storage-side counterpart that explicitly authorizes the subnet in the storage firewall. Even with a service endpoint enabled on the subnet, the storage account will reject traffic from that subnet unless the subnet appears in its 'Virtual networks' rule list. This rule accepts traffic based on the source subnet's identity, not on a private endpoint or public IP address.
- ✗
Create a private endpoint for the storage account.
Why it's wrong here
A private endpoint would place the storage account onto a private IP address in the subnet, which the scenario explicitly prohibits. It works by creating a network interface in the subnet that fronts the service, and all traffic to the storage account is routed to that private IP, bypassing the public endpoint entirely. This is a different network architecture than a service endpoint and introduces private IP dependency.
When this WOULD be correct
If the question required a private connection to the storage account without exposing it to the public internet, and the team is allowed to use private endpoints, then creating a private endpoint would be correct.
- ✗
Assign the Reader role to the subnet.
Why it's wrong here
Assigning the Reader role at the subnet scope only grants read-only management-plane permissions to the subnet resource itself; it has no effect on the storage account's network access or data-plane authorization. The storage firewall evaluates the source of the request, not any Azure RBAC role on the subnet, so a subnet will never be allowed to reach storage by virtue of a role assignment. Reader would not enable the storage connection at all.
When this WOULD be correct
In a scenario where a user or application in a subnet needs to read storage account configuration (e.g., list keys) but not access data, and network access is already open, assigning the Reader role to the subnet's managed identity or user would be correct.
- ✗
Turn on blob soft delete.
Why it's wrong here
Blob soft delete is a data-protection feature that keeps deleted blobs in a recoverable state for a retention period; it does not change the firewall rules or network authentication for the storage account. A request from the subnet would still be evaluated by the storage firewall and rejected if the subnet is not permitted. It therefore answers a completely different problem than granting network reachability.
When this WOULD be correct
In a scenario where an organization needs to protect against accidental blob deletion or overwrite, enabling blob soft delete would be correct. For example, a question might ask: 'Which feature should be enabled to allow recovery of accidentally deleted blobs within a retention period?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Enable the Microsoft.Storage service endpoint on the subnet.Correct answer▾
Why this is correct
Enabling a Microsoft.Storage service endpoint extends the identity of the subnet to the storage service, so storage accounts can permit access based on the subnet's virtual network address space rather than a specific private IP. This flag must be set on the subnet itself before a virtual network rule can be added to the storage account. Because the endpoint uses the public endpoint of the storage service, no private IP address is allocated, which matches the scenario's constraint.
✗Create a private endpoint for the storage account.Wrong answer — click to see why▾
Why this is wrong here
The question explicitly states the team does not want to use a private endpoint, so creating a private endpoint (option C) contradicts the requirement.
★ When this WOULD be the correct answer
If the question required a private connection to the storage account without exposing it to the public internet, and the team is allowed to use private endpoints, then creating a private endpoint would be correct.
Why candidates choose this
Candidates may confuse service endpoints with private endpoints, or think private endpoints are always the best security practice, ignoring the explicit constraint in the question.
✗Assign the Reader role to the subnet.Wrong answer — click to see why▾
Why this is wrong here
Assigning the Reader role to the subnet does not restrict network access to the storage account; it only grants read permissions to resources in that subnet, but the subnet itself is not authorized to access the storage account over the network.
★ When this WOULD be the correct answer
In a scenario where a user or application in a subnet needs to read storage account configuration (e.g., list keys) but not access data, and network access is already open, assigning the Reader role to the subnet's managed identity or user would be correct.
Why candidates choose this
Candidates may confuse role-based access control (RBAC) with network access control, thinking that assigning a role to a subnet grants network-level access to the storage account.
✗Turn on blob soft delete.Wrong answer — click to see why▾
Why this is wrong here
Blob soft delete is a data protection feature that allows recovering deleted blobs, but it does not restrict network access to the storage account. The question requires limiting access to a specific subnet, which soft delete cannot achieve.
★ When this WOULD be the correct answer
In a scenario where an organization needs to protect against accidental blob deletion or overwrite, enabling blob soft delete would be correct. For example, a question might ask: 'Which feature should be enabled to allow recovery of accidentally deleted blobs within a retention period?'
Why candidates choose this
Candidates may confuse data protection features with network security controls, or mistakenly think that soft delete includes access restrictions because it is a security-related setting in the storage account.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Virtual network
A virtual network is a software-based network that connects computers, servers, and devices over the internet or within a cloud environment, simulating a physical network without requiring dedicated hardware.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.