Courseiva

AZ-104 Implement and Manage Storage Practice Question

You are configuring a storage account named contosostore with a private endpoint. A virtual machine in a peered virtual network must access the storage account over the private endpoint. The private endpoint is deployed in a subnet named PrivateEndpointSubnet in the hub virtual network, and the VM is in a spoke virtual network that is peered with the hub. You have configured the private DNS zone privatelink.blob.core.windows.net and linked it to both virtual networks. However, the VM resolves the storage account FQDN to a public IP address instead of the private IP. What should you do to ensure the VM resolves the storage account to the private IP address?

⚠ Common exam trap

The trap here is focusing on network security settings like firewall rules when the actual issue is DNS resolution, which requires proper private DNS zone links and DNS server configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the private DNS zone is linked to the spoke virtual network and that the VM's DNS settings use Azure-provided DNS or a custom DNS that forwards to 168.63.129.16.

For a VM in a peered virtual network to resolve a storage account to its private endpoint IP, the private DNS zone must be linked to that virtual network, and the VM must use Azure-provided DNS or a custom DNS server that forwards to Azure DNS at 168.63.129.16. Without these conditions, the VM queries public DNS and receives the public IP, bypassing the private endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an A record in the public DNS zone for the storage account that points to the private IP address of the private endpoint.

    Why it's wrong here

    Creating an A record in a public DNS zone would expose the private IP publicly and is not how private endpoint DNS resolution works. The privatelink subdomain is used specifically to override public resolution for clients that use the private zone. This approach would not be effective and could cause security issues.

  • ✗

    Add a DNS forwarder on the hub virtual network that forwards queries for privatelink.blob.core.windows.net to Azure DNS.

    Why it's wrong here

    A DNS forwarder is not required when the private DNS zone is already linked to the virtual network. Azure DNS provides the private IP resolution directly through the linked private zone. Adding a forwarder would not change the resolution because the VM's DNS settings already point to Azure-provided DNS, which should use the linked zone.

  • ✓

    Verify that the private DNS zone is linked to the spoke virtual network and that the VM's DNS settings use Azure-provided DNS or a custom DNS that forwards to 168.63.129.16.

    Why this is correct

    For a VM in a peered network to resolve the private endpoint, the private DNS zone must be linked to the VM's virtual network, and the VM must use Azure DNS or a custom DNS server that forwards to Azure DNS. If the zone is linked but the VM uses a custom DNS server that does not forward, resolution fails. Ensuring both conditions are met guarantees the private IP is returned.

  • ✗

    Disable public network access on the storage account and enable the firewall to allow the spoke virtual network.

    Why it's wrong here

    Disabling public network access and configuring firewall rules controls network connectivity but does not affect DNS resolution. The VM would still resolve the public FQDN to a public IP unless the private DNS zone is properly linked and used. These actions address access control, not name resolution.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,053 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.