Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Exhibit

Storage account name: seccorpstorage
Property: publicNetworkAccess = Disabled
Property: defaultAction = Deny
Property: networkRules.defaultAction = Deny
Property: networkRules.ipRules = []
Property: networkRules.virtualNetworkRules = []

Refer to the exhibit. You need to ensure that the storage account 'seccorpstorage' is only accessible from a specific Azure virtual network. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a virtual network rule for the specific VNet

The correct answer is A: Add a virtual network rule for the specific VNet. In Azure Storage, network access restrictions are configured on the storage account's Networking blade, where you can add virtual network rules that allow access only from selected VNets and subnets; this directly satisfies the requirement that 'seccorpstorage' be accessible only from a specific Azure virtual network. Option B is incomplete because enabling the Microsoft.Storage service endpoint on the subnet is a prerequisite that makes the subnet eligible, but the storage account still needs the corresponding virtual network rule to actually restrict access. Option C is wrong because an IP-based firewall rule uses public IP addresses and does not restrict access to a specific VNet's private traffic. Option D is wrong because enabling public network access opens the account to public connectivity rather than limiting it to one VNet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a virtual network rule for the specific VNet

    Why this is correct

    Adding a virtual network rule for the specific VNet is the correct action because it explicitly authorizes traffic from that VNet's subnet(s) to the storage account. When the storage firewall is set to 'Selected networks', all traffic is denied by default, and a VNet rule carves out an exception that allows inbound requests from the trusted VNet only. This aligns with the requirement to restrict access to a single VNet while keeping public network access disabled.

  • ✗

    Enable the service endpoint for Microsoft.Storage on the VNet subnet

    Why it's wrong here

    Enabling the service endpoint for Microsoft.Storage on the subnet prepares the network path by making traffic to Azure Storage originate from the subnet's private IP addresses and traverse the Azure backbone. However, this action alone does not grant access; the storage account's firewall still evaluates every request and, without a matching virtual network rule, will reject traffic from that subnet. You must pair the service endpoint with an explicit VNet rule to actually authorize the traffic.

  • ✗

    Enable firewall and add an IP rule for the VNet's public IP

    Why it's wrong here

    Adding an IP rule for the VNet's public IP is ineffective because traffic originating from resources inside a VNet, such as VMs, uses private IP addresses from the subnet's address space, not the VNet's public IP (if one even exists). Azure Storage firewall IP rules match the public source IP of connections, and since VNet-to-storage traffic appears with a private source IP, the rule will never match. Thus, this approach would not allow any traffic from the VNet.

  • ✗

    Enable public network access and add a firewall rule

    Why it's wrong here

    Enabling public network access and adding a firewall rule would defeat the current security configuration because the storage account already has public network access disabled, meaning all external traffic is blocked. Re-enabling it exposes the storage account to the internet and expands the attack surface unnecessarily, while still not addressing the specific requirement to allow only a designated VNet. The correct path is to keep public network access disabled and use a VNet rule instead.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.