Courseiva
Implement and Manage StoragehardMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

Diagnostic settings on an Azure storage account must send logs to a destination storage account that has its firewall set to deny all public network access. The team cannot create a private endpoint, but the destination service is one of the Azure services that can bypass the firewall as a trusted Microsoft service. What should the administrator enable?

⚠ Common exam trap

It's easy for candidates to confuse service endpoints (Option A) with the trusted Microsoft services bypass, mistakenly thinking a service endpoint on the source subnet can grant access, when in fact the bypass is a distinct firewall exception that does not require any virtual network integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Allow trusted Microsoft services to bypass this firewall setting

The 'Allow trusted Microsoft services to bypass this firewall' setting enables specific Azure services, such as Azure Monitor or Azure Backup, to write diagnostic logs to a storage account even when the storage account's firewall blocks all public network access. This bypass is controlled at the Azure platform level and does not require a private endpoint or public IP, making it the only viable solution when the destination storage account denies all public traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A service endpoint on the destination storage account subnet

    Why it's wrong here

    A service endpoint secures outbound traffic from a specific Azure subnet to a PaaS service like Storage, but it does not grant access to the storage account when public network access is denied, nor does it serve as a trusted-service bypass. In this diagnostic scenario, the storage account is the source of data flowing to a trusted Microsoft service, so a service endpoint on the destination subnet is irrelevant to the required firewall exception. Even if one existed, it would not authorize the Microsoft service to reach the storage account through the firewall.

    When this WOULD be correct

    This option would be correct if the question asked: 'How to allow access to a storage account from a specific virtual network without using a private endpoint?' In that scenario, enabling a service endpoint on the source subnet and adding it to the storage account firewall rules would be the solution.

  • The Allow trusted Microsoft services to bypass this firewall setting

    Why this is correct

    This setting is designed for supported Microsoft services that need to reach a storage account even when public network access is denied. It allows the service to deliver data without opening the firewall broadly and without requiring a private endpoint. Because the scenario explicitly says the destination is a trusted Microsoft service, this is the correct and minimal change.

  • A shared access signature with read permission

    Why it's wrong here

    A shared access signature is an authorization token that grants fine-grained access to storage resources, but it operates at the data plane and is evaluated only after a request is allowed by the network firewall. The storage account's firewall blocks all public network traffic, regardless of the presence of a valid SAS, because network filtering occurs before any authentication check. Since the sending service is a trusted Microsoft service, the correct fix is to enable the firewall bypass, not to issue a read-permission SAS.

    When this WOULD be correct

    When the question asks for a method to grant time-limited, delegated access to a specific storage resource (e.g., blob, file share) without sharing the account key, and the destination does not require firewall bypass. For example: 'An application needs to read blobs from a storage account for 24 hours without using the account key.'

  • A private DNS zone linked to the workspace virtual network

    Why it's wrong here

    A private DNS zone only customizes name resolution for private endpoints, allowing a storage account to be reached via a private IP inside the virtual network. Since the scenario explicitly prevents creating a private endpoint, the DNS zone cannot establish connectivity and does nothing to change the storage account's firewall rule. The diagnostic settings delivery to a trusted Microsoft service relies on that service's own network path, not on DNS resolution in the workspace VNet.

    When this WOULD be correct

    This option would be correct in a scenario where an Azure service (e.g., Azure SQL Database) is configured with a private endpoint, and you need to ensure that the service's private IP address resolves correctly within a virtual network. The administrator would create a private DNS zone linked to the virtual network to enable custom DNS resolution for the private endpoint.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

The Allow trusted Microsoft services to bypass this firewall settingCorrect answer

Why this is correct

This setting is designed for supported Microsoft services that need to reach a storage account even when public network access is denied. It allows the service to deliver data without opening the firewall broadly and without requiring a private endpoint. Because the scenario explicitly says the destination is a trusted Microsoft service, this is the correct and minimal change.

A service endpoint on the destination storage account subnetWrong answer — click to see why

Why this is wrong here

A service endpoint on the destination storage account subnet would allow access from a specific virtual network, but the question requires bypassing the firewall for a trusted Microsoft service, not for a VNet. The destination storage account's firewall is set to deny all public access, and the source is a diagnostic setting, not a VNet.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'How to allow access to a storage account from a specific virtual network without using a private endpoint?' In that scenario, enabling a service endpoint on the source subnet and adding it to the storage account firewall rules would be the solution.

Why candidates choose this

Candidates may confuse service endpoints with the trusted Microsoft services bypass, thinking both allow access from Azure services. However, service endpoints are for VNet traffic, not for Azure platform services like diagnostic logs.

A shared access signature with read permissionWrong answer — click to see why

Why this is wrong here

A shared access signature (SAS) provides delegated access to a specific resource, but it does not bypass the storage account firewall. The firewall blocks all traffic unless explicitly allowed, and a SAS token does not override that restriction.

★ When this WOULD be the correct answer

When the question asks for a method to grant time-limited, delegated access to a specific storage resource (e.g., blob, file share) without sharing the account key, and the destination does not require firewall bypass. For example: 'An application needs to read blobs from a storage account for 24 hours without using the account key.'

Why candidates choose this

Candidates may confuse SAS with a mechanism to bypass firewalls because SAS tokens are often used to grant external access, but they do not affect network-level firewall rules.

A private DNS zone linked to the workspace virtual networkWrong answer — click to see why

Why this is wrong here

A private DNS zone linked to the workspace virtual network is used for custom domain name resolution within a virtual network, not for bypassing firewall rules on a storage account. The question requires enabling trusted Microsoft services to bypass the firewall, not DNS configuration.

★ When this WOULD be the correct answer

This option would be correct in a scenario where an Azure service (e.g., Azure SQL Database) is configured with a private endpoint, and you need to ensure that the service's private IP address resolves correctly within a virtual network. The administrator would create a private DNS zone linked to the virtual network to enable custom DNS resolution for the private endpoint.

Why candidates choose this

Candidates may confuse private DNS zones with private endpoints or think that DNS configuration is needed to allow access through a firewall, not realizing that the trusted Microsoft services bypass setting is the direct solution.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A backup job from an Azure service must write to a storage account that has the network firewall set to deny all public traffic. The team does not want to create a private endpoint for this workload. What should the administrator enable?

medium
  • A.Allow trusted Microsoft services to access the storage account
  • B.Add the backup server's public IP address to the storage firewall
  • C.Create a service endpoint on the subnet that hosts the backup job
  • D.Disable the storage account firewall temporarily during each backup window

Why A: Azure Storage firewalls include a special exception for 'Allow trusted Microsoft services to access this storage account'. When enabled, this exception permits Azure platform services—such as Azure Backup—to bypass the public network deny rule and write to the storage account without requiring a private endpoint. This works because the backup service runs on Microsoft-owned infrastructure that is authenticated and authorized at the control plane level, not via a public IP.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.