Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your company uses Azure Blob Storage to store sensitive documents. You need to prevent data exfiltration by ensuring that all access to the storage account is through Microsoft's private network. What should you configure?

⚠ Common exam trap

Candidates often confuse service endpoints (which still leave the public endpoint active) with private endpoints (which fully remove public access), leading them to choose option D or C, thinking they have achieved private network access when they have not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a private endpoint for the storage account and disable public network access.

Creating a private endpoint for the storage account assigns it a private IP from your virtual network, and disabling public network access ensures that all traffic to the storage account is routed through Microsoft's backbone network, preventing data exfiltration over the public internet. This configuration effectively isolates the storage account to your private network, meeting the requirement to block all public access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a network security group (NSG) to the subnet with a deny rule for internet traffic.

    Why it's wrong here

    An NSG is attached to a subnet or NIC and filters traffic for VMs and compute resources; it cannot be attached to an Azure Storage account. Storage accounts are PaaS services with their own publicly routable endpoint, so a deny rule for internet traffic in an NSG has no bearing on connections that target the storage account from outside that subnet. Even traffic from an allowed subnet would still traverse the storage account's public endpoint unless the account's own network rules are configured.

  • ✓

    Create a private endpoint for the storage account and disable public network access.

    Why this is correct

    A private endpoint places the storage account on a private IP inside your VNet, and all requests to that IP are forwarded over Microsoft's backbone through Private Link, never the public internet. Disabling public network access then closes the storage account's externally visible endpoint, so only connections through the private endpoint are successful. This combination gives both private connectivity and exfiltration protection because the resource is no longer routable from any public source.

  • ✗

    Set the firewall to deny all and add a rule to allow only your VNet's public IP.

    Why it's wrong here

    Configuring the storage firewall to allow a public IP does not create a private path; the source sends traffic over the internet to the storage account's public endpoint, which Microsoft then receives on the Azure boundary. Denying all other IPs only restricts which source addresses are permitted, but the traffic still leaves your network and crosses the public internet. Additionally, the phrase 'VNet's public IP' is inaccurate because VNets do not have public IPs—you would be allowing a VM's or NAT gateway's public IP, which is not an Azure backbone path.

  • ✗

    Enable service endpoints and configure a service endpoint policy.

    Why it's wrong here

    Service endpoints replace the public source IP with the VNet identity when traffic goes from a subnet to Azure Storage, but the storage account still exposes a public endpoint and is still reachable from anywhere unless the firewall is locked down. A service endpoint policy can only control which storage accounts are allowed as egress destinations from your VNet; it does not prevent a compromised storage account from being accessed or its data copied to a public destination. Since the public endpoint remains, data exfiltration is still possible if an attacker has credentials and can reach the endpoint from the internet.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.