Courseiva
Secure networking →hardMultiple Choice

AZ-500 Secure networking Practice Question

A company plans to use Azure Private Endpoint to securely connect to an Azure SQL Database from an on-premises network via ExpressRoute. The private endpoint is deployed in a hub virtual network. The on-premises network is connected to the hub via ExpressRoute. What additional configuration is needed to ensure on-premises clients can resolve the private endpoint's DNS name?

⚠ Common exam trap

It's easy for candidates to assume that ExpressRoute alone provides full connectivity and DNS resolution, but they overlook the critical requirement of DNS configuration to ensure on-premises clients resolve the private endpoint's private IP instead of the public IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a DNS forwarder on-premises to forward the private link domain to Azure DNS.

Azure Private Endpoint requires DNS resolution to map the private endpoint's private IP address to the fully qualified domain name (FQDN) of the Azure SQL Database. On-premises clients connected via ExpressRoute cannot resolve the private link domain (e.g., `*.database.windows.net`) to the private IP unless a DNS forwarder is configured on-premises to forward queries for the `privatelink.database.windows.net` zone to Azure DNS (168.63.129.16). This ensures that DNS queries from on-premises resolve to the private endpoint IP instead of the public IP of the SQL Database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a DNS forwarder on-premises to forward the private link domain to Azure DNS.

    Why this is correct

    On-premises clients must resolve the resource's FQDN to the private IP that Azure Private Link assigns. The public Azure DNS endpoint normally returns a public IP, so the on-prem DNS suffix should include the 'privatelink' zone and forward those queries to Azure DNS (e.g., via Azure Private DNS Resolver or the DNS IP 168.63.129.16) after the ExpressRoute connection is established. This conditional forwarder enables seamless name resolution without exposing the private IP publicly.

  • ✗

    Configure a network security group to allow inbound traffic from on-premises to the private endpoint.

    Why it's wrong here

    NSGs on the subnet hosting a private endpoint are not evaluated for traffic destined to that endpoint because private endpoint network policies are disabled by default. Consequently, an NSG permitting inbound from on-premises would have no effect on whether the SQL connection succeeds. If you need to restrict access, apply the NSG to the source subnet or enforce service-level authentication/authorization such as Microsoft Entra ID or SQL firewall rules.

  • ✗

    Deploy a VPN gateway in the hub VNet for additional encryption.

    Why it's wrong here

    Deploying a VPN gateway adds an IPsec tunnel that is unnecessary when ExpressRoute is present and does not alter the DNS resolution path that is causing the failure. ExpressRoute already traverses the Microsoft backbone as a private layer-2 path; switching to a VPN gateway would not make the FQDN resolve to the private endpoint's IP and would increase complexity and latency. The correct next step is to fix DNS resolution, not to add another connectivity edge.

  • ✗

    Add a public DNS record for the SQL Database pointing to the private endpoint IP.

    Why it's wrong here

    Creating a public DNS A record that points the SQL FQDN to the private endpoint's RFC1918 address is incorrect because private IPs are non-routable from the internet and such a record would expose the internal topology, defeating the purpose of a private endpoint. It would also be ignored by Azure's built-in DNS hierarchy, which already CNAMEs the service to the privatelink domain. The proper approach is to keep the private IP in a private DNS zone or a forwarder that is only visible to the on-premises resolver.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.