Courseiva

AZ-305 Design data storage solutions Practice Question

Exhibit

Refer to the exhibit. The following is an Azure CLI command output:
{
  "id": "/subscriptions/.../resourceGroups/rg1/providers/Microsoft.Storage/storageAccounts/st1",
  "kind": "StorageV2",
  "properties": {
    "accessTier": "Hot",
    "supportsHttpsTrafficOnly": true,
    "encryption": {
      "keySource": "Microsoft.Storage",
      "services": {
        "blob": {
          "enabled": true,
          "keyType": "Account"
        },
        "file": {
          "enabled": true,
          "keyType": "Account"
        }
      }
    },
    "networkAcls": {
      "bypass": "AzureServices",
      "defaultAction": "Deny",
      "ipRules": [],
      "virtualNetworkRules": []
    }
  }
}

Refer to the exhibit. You need to enable public access to the storage account for a specific IP address while keeping the default action as Deny. What should you do?

⚠ Common exam trap

Many exam-takers think they must change the default action to Allow and then add a Deny rule, but Azure Storage firewall does not support explicit Deny rules for IP addresses—only Allow rules—so the correct approach is to keep the default as Deny and add an Allow rule for the specific IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an IP rule with the specific IP address to the ipRules array.

The Azure Storage account firewall allows you to create IP rules that grant access to specific public IP addresses or ranges while keeping the default action as Deny. By adding an IP rule with the specific IP address to the `ipRules` array, you explicitly allow that IP through the firewall, and all other traffic is denied by the default rule. This is the standard method to enable selective public access without changing the default deny behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the bypass to None to allow all traffic.

    Why it's wrong here

    The bypass property in Azure network ACLs only governs whether trusted Microsoft services can bypass the firewall; setting it to None does not influence how the firewall treats public IP traffic. It simply revokes the automatic exception for Azure platform services, meaning even those services would be subject to the default action (Deny). Public IP access is governed by explicit IP rules and the defaultAction, not by the bypass setting, so this change cannot allow all traffic and would instead further restrict service access.

  • ✗

    Set the networkAcls to an empty list to remove restrictions.

    Why it's wrong here

    The networkAcls object is not a list of firewall rules; it is a structured object containing the defaultAction, bypass, ipRules, and virtualNetworkRules. Setting it to an empty list (or clearing its contents) is invalid or would remove the entire network ACL configuration, leaving the resource without defined access controls. Even if it removed restrictions, it would open the resource to all public traffic, not just the intended specific IP, and it would not satisfy the requirement for granular, IP-based public access.

  • ✓

    Add an IP rule with the specific IP address to the ipRules array.

    Why this is correct

    With defaultAction set to Deny, only traffic explicitly matched by an IP rule in the ipRules array is allowed. Adding a rule with the specific public IP address (or CIDR range) and action Allow creates a narrow exception for that source, while all other public traffic continues to be denied. This is the standard way to enable public access for a particular client while maintaining a secure, deny-by-default posture; the rule permits only the specified IP and does not alter the default behavior.

  • ✗

    Change the defaultAction to Allow and remove the Deny rule.

    Why it's wrong here

    Changing the defaultAction from Deny to Allow reverses the security model: any IP address that does not match an explicit deny rule will be permitted, which means the resource would become publicly accessible to the entire internet. Removing the Deny rule would leave no restrictions at all, as the default action of Allow applies to all unmatched traffic. This approach fails to restrict access to the specific IP and instead opens the resource broadly, violating the requirement for controlled public access.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.