You need to restrict access to an Azure Storage account so that only traffic from a specific virtual network is allowed. What should you configure?
The Storage account firewall and virtual network settings are the correct service-level control because they allow you to switch the storage account from 'All networks' to 'Selected networks,' then add a virtual network rule that permits traffic only from a specific virtual network (or subnet). This default-deny configuration explicitly blocks all other public IP ranges and network traffic that does not match an allow rule, thereby achieving the required restriction.
Why this answer
Azure Storage accounts have a built-in firewall that can be configured to restrict access based on source IP addresses or virtual network (VNet) rules. By enabling the storage account firewall and adding a rule that allows traffic only from a specific VNet/subnet, you effectively block all other traffic, including internet traffic, while permitting requests from the designated VNet. This is the native Azure method for network-level access control to storage accounts.
Exam trap
The trap here is that candidates often confuse the storage account firewall with network security groups (NSGs) or private endpoints, thinking that an NSG on a subnet can control access to a PaaS service like Storage, or that a private endpoint alone restricts access without also disabling public network access.
How to eliminate wrong answers
Option A is wrong because Azure Firewall application rules are used to allow or deny outbound HTTP/HTTPS traffic from a VNet to specific FQDNs, not to restrict inbound access to an Azure Storage account. Option C is wrong because a private endpoint connection assigns a private IP address to the storage account within a VNet, but it does not by itself restrict access; it must be combined with disabling public network access or configuring the storage account firewall to deny all public traffic. Option D is wrong because a Network Security Group (NSG) on a subnet can filter traffic to and from resources within that subnet, but it cannot directly restrict access to an Azure Storage account, which is a PaaS service with its own firewall; NSGs do not apply to the storage account's public endpoint.