AZ-500 Azure Private Endpoint Practice Question
A Defender for Cloud recommendation requires enabling private endpoints for a storage account. Which security risk is primarily reduced?
⚠ Common exam trap
The trap is that candidates may incorrectly associate private endpoints with identity protection (Option C) because private endpoints limit network access, which could indirectly reduce identity attacks. However, the question asks for the primary risk reduced, which is specifically public internet exposure (Option B). Private endpoints are a network security control, not an identity control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Public internet exposure of the storage service endpoint
Enabling private endpoints for a storage account connects it to an Azure Virtual Network over a private IP address, eliminating access from the public internet. This directly reduces the risk of public internet exposure of the storage service endpoint (Option B). The primary risk addressed is network-level exposure, not identity-related risks like unauthorized changes to Microsoft Entra ID users (Option C). While private endpoints can contribute to a defense-in-depth strategy, the most immediate and primary risk reduction is the removal of public network accessibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VM disk fragmentation
Why it's wrong here
VM disk fragmentation is unrelated to private endpoints; it's a performance issue, not a security risk.
- ✓
Public internet exposure of the storage service endpoint
Why this is correct
Correct. Private endpoints eliminate public internet access to the storage account, directly reducing the risk of unauthorized network-based attacks via the public endpoint.
- ✗
Unauthorized changes to Microsoft Entra ID users
Why it's wrong here
Incorrect. Unauthorized changes to Microsoft Entra ID users are an identity and access management risk. While network isolation can help prevent some attack vectors, the primary risk reduced by private endpoints is network exposure, not identity compromise.
- ✗
Excessive Log Analytics ingestion
Why it's wrong here
Excessive Log Analytics ingestion is a cost or performance concern, not a security risk addressed by private endpoints.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.