A payroll application in a VNet must access an Azure Storage account containing confidential blobs. The security team requires the storage account to be reachable only over a private IP, and public network access must be disabled. Which feature should the administrator implement?
A private endpoint gives the storage account a private IP address from the VNet address space, allowing traffic to stay on private connectivity. This matches the requirement to disable public network access while still letting the application reach blob data. The private endpoint also integrates with DNS so the storage FQDN resolves to the private address. That design is the correct choice when access must be restricted to a private path only.
Why this answer
A private endpoint assigns the storage account a private IP address from the VNet, enabling secure access over a private connection while completely disabling public network access. This meets the security team's requirement because traffic never traverses the public internet, and the storage account's firewall can be configured to deny all public traffic.
Exam trap
The trap here is that candidates confuse service endpoints with private endpoints, not realizing that service endpoints still use the public endpoint and cannot disable public network access, whereas private endpoints provide a true private IP and full public access disablement.
Why the other options are wrong
A service endpoint does not provide a private IP; it allows access over the public endpoint but restricts it to the VNet. The requirement is to disable public network access entirely, which only a private endpoint can achieve.
A shared access signature (SAS) provides delegated access over the public endpoint, but the question requires public network access to be disabled and only private IP access allowed. SAS does not enforce private-only connectivity.