Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Azure Private Endpoint Practice Question

A Defender for Cloud recommendation requires enabling private endpoints for a storage account. Which security risk is primarily reduced?

⚠ Common exam trap

The trap is that candidates may incorrectly associate private endpoints with identity protection (Option C) because private endpoints limit network access, which could indirectly reduce identity attacks. However, the question asks for the primary risk reduced, which is specifically public internet exposure (Option B). Private endpoints are a network security control, not an identity control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Public internet exposure of the storage service endpoint

Enabling private endpoints for a storage account connects it to an Azure Virtual Network over a private IP address, eliminating access from the public internet. This directly reduces the risk of public internet exposure of the storage service endpoint (Option B). The primary risk addressed is network-level exposure, not identity-related risks like unauthorized changes to Microsoft Entra ID users (Option C). While private endpoints can contribute to a defense-in-depth strategy, the most immediate and primary risk reduction is the removal of public network accessibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VM disk fragmentation

    Why it's wrong here

    VM disk fragmentation is unrelated to private endpoints; it's a performance issue, not a security risk.

  • ✓

    Public internet exposure of the storage service endpoint

    Why this is correct

    Correct. Private endpoints eliminate public internet access to the storage account, directly reducing the risk of unauthorized network-based attacks via the public endpoint.

  • ✗

    Unauthorized changes to Microsoft Entra ID users

    Why it's wrong here

    Incorrect. Unauthorized changes to Microsoft Entra ID users are an identity and access management risk. While network isolation can help prevent some attack vectors, the primary risk reduced by private endpoints is network exposure, not identity compromise.

  • ✗

    Excessive Log Analytics ingestion

    Why it's wrong here

    Excessive Log Analytics ingestion is a cost or performance concern, not a security risk addressed by private endpoints.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.