AZ-500 Secure compute, storage, and databases Practice Question
Your organization is using Azure Database for MySQL. You need to ensure that only traffic from Azure services and specific client IP addresses can connect to the database. What should you configure?
⚠ Common exam trap
Many candidates confuse network-level controls (NSGs, service endpoints) with the PaaS firewall, mistakenly thinking they can apply NSG rules to a PaaS database or that service endpoints alone can restrict access to specific IPs without additional firewall configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewall rules with 'Allow access to Azure services' enabled and specific IP rules
Azure Database for MySQL uses firewall rules to control access at the server level. Enabling 'Allow access to Azure services' permits connections from Azure internal IP ranges, while adding specific client IP rules restricts access to only those addresses. This dual configuration meets the requirement to allow traffic from Azure services and specific client IPs while blocking all other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID authentication
Why it's wrong here
Microsoft Entra ID authentication governs the identity of the principal trying to log in—it validates who you are, not where your traffic originates. This mechanism does not inspect source IP addresses or network boundaries, so a user with valid AAD credentials from any public IP could still reach the server if the firewall permits it. Thus, AAD authentication complements, but never replaces, network-level controls like firewall rules.
- ✗
Virtual Network service endpoints
Why it's wrong here
Virtual Network service endpoints extend your VNet's identity to Azure Database for MySQL, allowing you to restrict the database to traffic from a specific VNet subnet. However, they do not provide fine-grained IP-based allowlisting for individual client machines, nor do they automatically enable access from all Azure services. Since the scenario emphasizes IP-specific access control rather than VNet integration, service endpoints are not the appropriate solution.
- ✗
Network Security Group (NSG) rules on the subnet
Why it's wrong here
Network Security Group (NSG) rules filter traffic at the subnet or network interface level for resources inside a virtual network, such as VMs. Azure Database for MySQL is a managed PaaS service with its own firewall layer; NSGs attached to a subnet do not directly govern inbound traffic to the database's public endpoint. Applying an NSG would only matter when using private-link or service-endpoint scenarios, and it still cannot replace the database firewall's IP allowlist.
- ✓
Firewall rules with 'Allow access to Azure services' enabled and specific IP rules
Why this is correct
The correct network access control for Azure Database for MySQL is the server-level firewall, which accepts connections only from explicitly allowed IP ranges. Enabling 'Allow access to Azure services' adds the special Azure internal IP range, permitting connections from other Azure services without a specific public IP. Adding precise IP rules for client workstations or office ranges further restricts the database to known sources, making this the suitable mechanism for the described requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.