AZ-500 Secure compute, storage, and databases Practice Question
You need to prevent data exfiltration from Azure Storage accounts by controlling which networks can access them. Which Azure feature should you use?
⚠ Common exam trap
It's easy for candidates to confuse network-level access control (storage firewalls and VNet rules) with identity-based access control (SAS tokens) or connectivity solutions (Private Link), leading them to select Azure Firewall or Private Link instead of the dedicated storage network security feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Storage firewalls and virtual network rules
Azure Storage firewalls and virtual network rules (Option D) are the correct choice because they allow you to restrict access to your storage account based on specific IP addresses, IP ranges, or virtual networks, effectively preventing data exfiltration by blocking unauthorized network traffic. This feature works at the network layer, enabling you to create a perimeter around your storage account that only allows trusted sources to connect, which directly addresses the requirement to control network-level access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Storage shared access signatures (SAS)
Why it's wrong here
SAS tokens are URL-based credentials that grant delegated access to storage resources, but they do not impose any network-level restrictions. Even with a SAS, a user with the token can access the storage account from any IP address or network, so it cannot prevent data exfiltration from an external or unauthorized network. Restricting exfiltration requires limiting the network origin of requests, which is outside SAS's capabilities.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a managed, cloud-native network security service that filters traffic between virtual networks and outbound/inbound internet connections, but it operates at the network and application layers rather than as a control plane for Azure Storage access. While it can restrict general network traffic, it does not enforce authorization or network rules specific to the storage account, such as allowing only selected virtual networks or IP ranges. Storage access is governed by the storage account's own firewall and virtual network rules, so Azure Firewall alone cannot stop exfiltration from a storage account.
- ✗
Azure Private Link
Why it's wrong here
Azure Private Link exposes the storage account through a private endpoint, giving it a private IP address inside your virtual network and removing the need for public internet connectivity. However, it does not automatically disable the storage account's public endpoint or enforce network ACLs, so the storage account may remain reachable from public networks unless you separately block it. Malicious actors with appropriate credentials can still exfiltrate data via the public endpoint, meaning Private Link alone cannot prevent exfiltration without additional network restrictions.
- ✓
Azure Storage firewalls and virtual network rules
Why this is correct
Azure Storage firewalls and virtual network rules allow you to define a set of virtual networks and IP address ranges that are permitted to access the storage account, and all other requests are denied. This directly controls the network origin of clients, so if an attacker outside your trusted networks tries to connect using the storage account endpoint, the request is blocked before it reaches the data. By restricting access to only trusted networks, this feature effectively prevents data exfiltration from unauthorized network locations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.