Private Endpoint vs Service Endpoint: What's the Difference?
A company wants an Azure Storage account to be reachable privately from a virtual network. Which two statements about a private endpoint are correct? Select two.
Quick Answer
The correct answer is that a private endpoint assigns the Azure Storage service a private IP address from your virtual network’s subnet, and a private DNS zone is commonly used so the service name resolves to that private IP. This works because the private endpoint effectively brings the storage account into your virtual network via a network interface, ensuring all traffic stays on the Microsoft backbone and never touches the public internet. On the AZ-104 exam, this concept tests your understanding of secure connectivity options, often appearing in scenario-based questions where you must choose between private and service endpoints. A common trap is confusing service endpoints, which only extend the network boundary over the internet without assigning a private IP, with private endpoints that provide true isolation. Remember the memory tip: “Private endpoint = private IP inside your VNet; service endpoint = public IP with a direct route.”
⚠ Common exam trap
Candidates often confuse private endpoints with service endpoints, thinking both provide a private IP address, but only private endpoints assign a private IP from the VNet, while service endpoints rely on public IPs with network security group (NSG) restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage service gets a private IP address in the selected virtual network.
Option A is correct because an Azure Private Endpoint creates a network interface (NIC) in a chosen subnet of the virtual network and assigns the target PaaS service (here, Azure Storage) a private IP address from that subnet's address space, so traffic reaches the storage account over the private IP rather than the public endpoint. Option D is correct because clients normally address the storage account by its public FQDN (e.g., <account>.blob.core.windows.net), so a private DNS zone such as privatelink.blob.core.windows.net is linked to the virtual network to override that name and resolve it to the endpoint's private IP; without this, name resolution would still return the public address. Option B is wrong because the whole point of a private endpoint is private connectivity from within the VNet, and the client VM does not need a public IP address. Option C is wrong because DNS configuration is still required — a private endpoint does not automatically handle name resolution. Option E is wrong because a service endpoint extends the VNet identity to the service over the Azure backbone while the service keeps its public IP, whereas a private endpoint gives the service a private IP in the VNet; they are distinct features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The storage service gets a private IP address in the selected virtual network.
Why this is correct
A private endpoint provisions a network interface with a private IP address from the selected virtual network's subnet, fronting the storage service. Traffic then reaches the storage account over that private address, satisfying the requirement for private reachability.
- ✗
The virtual machine that reaches the service must have its own public IP address.
Why it's wrong here
A private endpoint gives the storage account a private IP inside the virtual network, so the client VM needs no public IP; traffic stays on the Azure backbone. It is tempting because public endpoints require internet routing, but that is the model private endpoints deliberately replace.
When this WOULD be correct
In a scenario where a virtual machine must access an Azure service that does not support private endpoints (e.g., a legacy service) and the only connectivity option is via the internet, the VM would need a public IP address for outbound traffic.
- ✗
A private endpoint replaces the need for any DNS configuration.
Why it's wrong here
Private endpoints still require DNS configuration: the private DNS zone (privatelink.blob.core.windows.net) must resolve the storage FQDN to the endpoint's private IP, otherwise clients resolve the public address. It is tempting because private endpoints remove public exposure, but DNS records remain mandatory for name resolution.
When this WOULD be correct
In a scenario where the question asks about a feature that eliminates the need for public DNS resolution for Azure PaaS services, and the correct answer is 'Azure Private Link automatically handles DNS configuration for private endpoints,' but that is not accurate; however, if the question were 'Which feature allows you to use a custom DNS server to resolve the storage account name to a private IP without manual DNS records?' the answer would be 'private DNS zone,' not the endpoint itself.
- ✓
A private DNS zone is commonly used so the service name resolves to the private IP.
Why this is correct
A private DNS zone linked to the virtual network maps the storage service name to the private endpoint's IP, so clients resolve the service to the private address rather than its public one. This satisfies private name resolution for the storage account.
- ✗
A private endpoint and a service endpoint are the same feature.
Why it's wrong here
A private endpoint creates a private IP address in your subnet via Azure Private Link, whereas a service endpoint extends the virtual network identity to the service's public endpoint over the Azure backbone; they differ in mechanism and DNS behaviour. It is tempting because both remove public internet exposure, so they are easily conflated.
When this WOULD be correct
If the question asked 'Which two statements about service endpoints are correct?' and included an option stating 'A service endpoint and a private endpoint are the same feature,' this would be incorrect; however, no scenario makes this statement correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓The storage service gets a private IP address in the selected virtual network.Correct answer▾
Why this is correct
A private endpoint provisions a network interface with a private IP address from the selected virtual network's subnet, fronting the storage service. Traffic then reaches the storage account over that private address, satisfying the requirement for private reachability.
✗The virtual machine that reaches the service must have its own public IP address.Wrong answer — click to see why▾
Why this is wrong here
A private endpoint does not require the virtual machine to have a public IP address; traffic stays within the Microsoft backbone and never traverses the internet.
★ When this WOULD be the correct answer
In a scenario where a virtual machine must access an Azure service that does not support private endpoints (e.g., a legacy service) and the only connectivity option is via the internet, the VM would need a public IP address for outbound traffic.
Why candidates choose this
Candidates may confuse private endpoints with traditional internet-based access, assuming that private connectivity still requires a public IP for the client.
✗A private endpoint replaces the need for any DNS configuration.Wrong answer — click to see why▾
Why this is wrong here
A private endpoint does not replace DNS configuration; it requires DNS resolution to map the storage account's FQDN to the private IP, often using a private DNS zone.
★ When this WOULD be the correct answer
In a scenario where the question asks about a feature that eliminates the need for public DNS resolution for Azure PaaS services, and the correct answer is 'Azure Private Link automatically handles DNS configuration for private endpoints,' but that is not accurate; however, if the question were 'Which feature allows you to use a custom DNS server to resolve the storage account name to a private IP without manual DNS records?' the answer would be 'private DNS zone,' not the endpoint itself.
Why candidates choose this
Candidates may think that because the private endpoint assigns a private IP, DNS configuration is automatically handled, overlooking that DNS resolution still needs explicit setup to ensure the service name resolves to the private IP.
✗A private endpoint and a service endpoint are the same feature.Wrong answer — click to see why▾
Why this is wrong here
Private endpoints and service endpoints are distinct features: private endpoints provide a private IP in the VNet, while service endpoints extend the VNet's identity to the service over the public endpoint.
★ When this WOULD be the correct answer
If the question asked 'Which two statements about service endpoints are correct?' and included an option stating 'A service endpoint and a private endpoint are the same feature,' this would be incorrect; however, no scenario makes this statement correct.
Why candidates choose this
Candidates may confuse the two features because both are used to secure Azure services to a virtual network, leading to the mistaken belief they are identical.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Blob Versioning and Soft Delete
Key term
Private IP address
A private IP address is a non-internet-routable address used within a local network to identify devices and allow them to communicate with each other without direct exposure to the public internet.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,053 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-104
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A storage account must remain on its public endpoint, but only one Azure subnet named AppSubnet should be allowed to access it from Azure. No private IP is required. Which two actions should the administrator take? Select two.
medium- ✓ A.Enable the Microsoft.Storage service endpoint on AppSubnet.
- ✓ B.Configure the storage account networking firewall to allow the selected virtual network and subnet.
- C.Create a private endpoint and disable public network access.
- D.Link a private DNS zone to AppSubnet.
- E.Assign the Reader RBAC role to AppSubnet.
Why A: Enabling the Microsoft.Storage service endpoint on AppSubnet allows traffic from that subnet to the storage account over the Azure backbone network, using the public endpoint while restricting access to only that subnet. Option B is correct because configuring the storage account's networking firewall to allow the selected virtual network and subnet explicitly permits traffic from AppSubnet while blocking all other public access, meeting the requirement to keep the public endpoint but limit access to one subnet.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.