Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

A storage account should be reachable only from a specific subnet over the Microsoft backbone, while keeping the public endpoint firewall restricted. Which feature should be used?

⚠ Common exam trap

Watch out — candidates often confuse service endpoints with private endpoints, but the question explicitly requires keeping the public endpoint firewall restricted, which is exactly what service endpoints support by allowing selective subnet access through firewall rules without creating a private IP connection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service endpoint for Microsoft.Storage with storage firewall rules

A service endpoint for Microsoft.Storage extends your virtual network private address space and the identity of your VNet to the Azure Storage service over the Microsoft backbone. By combining the service endpoint with a storage firewall rule that restricts access to only that specific subnet, you ensure the storage account is reachable only from that subnet while keeping the public endpoint firewall restricted to deny all other traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application Security Group

    Why it's wrong here

    Application Security Groups (ASGs) group VM NICs and are used with network security group rules to control traffic between workloads; they do not apply to PaaS resources like Azure Storage nor configure storage account firewall/network access. Thus, using an ASG cannot make the storage account reachable only from a specific network or subnet; the storage account's network controls are separate from NSG/ASG semantics.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion provides secure RDP/SSH access to VMs within a virtual network via TLS, but it is a management plane gateway; it does not restrict data plane access to a storage account. Even if Bastion is deployed, the storage account's public endpoint remains controlled by storage firewall and service endpoints, so Bastion alone cannot enforce that only a specific source can reach the storage account.

  • ✓

    Service endpoint for Microsoft.Storage with storage firewall rules

    Why this is correct

    A service endpoint for Microsoft.Storage extends the virtual network identity to the storage account, and when combined with storage firewall rules that deny all traffic except from the chosen subnet(s), it ensures the storage account is reachable only from that specific virtual network/subnet. This is the standard Azure mechanism for restricting PaaS storage to a private network segment, as the firewall rule blocks public internet and other sources while the service endpoint routes traffic from the subnet.

  • ✗

    Public IP prefix

    Why it's wrong here

    A public IP prefix is a contiguous range of public IP addresses that you can assign to Azure resources like load balancers or VMs, but it does not, by itself, filter access to a storage account. Although storage firewall rules can allow specific public IPs or ranges, a prefix alone is not a policy that makes the storage account reachable only from it; you would still need to explicitly configure the storage firewall, and the prefix is not the appropriate control for subnet-specific access that service endpoints provide.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.