AZ-500 Secure networking Practice Question
You need to restrict access to an Azure Storage account so that only traffic from a specific virtual network is allowed. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse the storage account firewall with network security groups (NSGs) or private endpoints, thinking that an NSG on a subnet can control access to a PaaS service like Storage, or that a private endpoint alone restricts access without also disabling public network access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Storage account firewall and virtual network settings
Azure Storage accounts have a built-in firewall that can be configured to restrict access based on source IP addresses or virtual network (VNet) rules. By enabling the storage account firewall and adding a rule that allows traffic only from a specific VNet/subnet, you effectively block all other traffic, including internet traffic, while permitting requests from the designated VNet. This is the native Azure method for network-level access control to storage accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall application rule
Why it's wrong here
Azure Firewall application rules operate at the application layer (Layer 7) to filter traffic based on Fully Qualified Domain Names (FQDNs), whereas restricting access by source network identity requires configuring Storage account firewalls and virtual networks. You would use application rules when you need to permit or deny web-based traffic to specific service endpoints via an Azure Firewall, rather than managing the underlying network layer for a storage resource.
- ✓
Storage account firewall and virtual network settings
Why this is correct
The Storage account firewall and virtual network settings are the correct service-level control because they allow you to switch the storage account from 'All networks' to 'Selected networks,' then add a virtual network rule that permits traffic only from a specific virtual network (or subnet). This default-deny configuration explicitly blocks all other public IP ranges and network traffic that does not match an allow rule, thereby achieving the required restriction.
- ✗
Private endpoint connection
Why it's wrong here
A private endpoint connection gives the storage account a private IP address inside your virtual network, enabling traffic to reach it over the Microsoft backbone without traversing the public internet. However, the private endpoint itself does not restrict access: the storage account's public endpoint remains available by default, so unless you also disable public network access or configure the storage account firewall to deny all public traffic, clients can still connect from any network.
- ✗
Network security group (NSG) on the subnet
Why it's wrong here
A network security group (NSG) on a subnet filters traffic at the network interface level for VMs and other resources inside that virtual network, but it does not control access to Azure PaaS services like Storage because the storage account's data plane is not hosted in the subnet. Even when a service endpoint is enabled, the NSG only affects traffic leaving the subnet; the decisive access control is the storage account's firewall rule that must explicitly allow the subnet, so an NSG alone cannot restrict access to the storage account.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.