AZ-500 Secure compute, storage, and databases Practice Question
Exhibit
{
"properties": {
"networkAcls": {
"bypass": "AzureServices",
"defaultAction": "Deny",
"ipRules": [
{
"action": "Allow",
"value": "203.0.113.0/24"
}
],
"virtualNetworkRules": []
}
}
}Refer to the exhibit. You are configuring network access for an Azure Storage account. After applying this configuration, users report that they cannot access the storage account from their on-premises network (public IP: 198.51.100.50). What is the most likely reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's public IP address is not in the allowed IP rules
The correct answer is D: the user's public IP address is not in the allowed IP rules. When an Azure Storage account firewall is configured with selected networks, only traffic from explicitly listed public IP addresses (or ranges) and permitted virtual networks is allowed; since the on-premises public IP 198.51.100.50 is not included in the allowed IP rules, requests are denied. Option A is not the likely cause because a private endpoint would affect access over the private link rather than simply blocking an on-premises public IP, and the scenario points to firewall IP filtering. Option B is incorrect because the AzureServices bypass applies to trusted Microsoft services, not to on-premises clients. Option C is incorrect because missing virtual network rules would not matter for an on-premises client connecting over the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The storage account is configured with a private endpoint
Why it's wrong here
The exhibit shows a firewall configuration with IP-based network rules, not a private endpoint. A private endpoint would assign a private IP address to the storage account within a virtual network, and access would be over the Microsoft backbone network rather than the public internet. Since the user is reaching the storage account from a public IP (198.51.100.50) and the configured rule is an IP allow rule, the denial is due to IP filtering, not the absence or presence of a private endpoint.
- ✗
The bypass for AzureServices is not configured correctly
Why it's wrong here
The 'Microsoft.AzureServices' bypass permits trusted Azure services (e.g., Azure Logic Apps, Azure Backup) to access the storage account even when the firewall is enabled, but it does not extend to arbitrary users on the internet. Even if the bypass were misconfigured, it would not affect an on-premises user's public IP address because that bypass only applies to Azure service endpoints, not end-user client traffic. The failure is caused by the user's IP not matching the allow list, not by bypass settings.
- ✗
The virtual network rules are missing
Why it's wrong here
Virtual network rules allow access only from subnets that have a service endpoint enabled. These rules are optional and only apply when traffic originates from within the specified virtual network. The user in this scenario is connecting from a public IP address (198.51.100.50) that is not part of any virtual network, so even if VNet rules were present, they would not grant access to this user. The relevant rule is the IP allow rule, which explicitly excludes the user's IP.
- ✓
The user's public IP address is not in the allowed IP rules
Why this is correct
The storage account's firewall has an IP allow rule only for 203.0.113.0/24. The user's public IP address is 198.51.100.50, which falls outside that CIDR range. Because the default action for the firewall is to deny all traffic that does not match an allow rule, the request is blocked. The IP must be added to the allowed range, or the user must use a permitted network path.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.