A private endpoint for storage1 is deployed in Subnet1 of VNet1. Site1 (on-premises) is connected to VNet1 over a Site-to-Site VPN. You want to control access from Site1 to storage1 by using network security groups (NSGs). What is the first action you should take?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable/configure the network policy for private endpoints on Subnet1..
Why this is the answer
To control access to a private endpoint resource using Network Security Groups (NSGs) from an on-premises network, you must enable the network policy for private endpoints on the subnet where the private endpoint is deployed. This setting allows NSGs to be applied to the private endpoint's network interface, enabling granular control over inbound and outbound traffic. Without this policy enabled, NSGs associated with Subnet1 will not filter traffic destined for or originating from the private endpoint, meaning your desired access control from Site1 to storage1 via NSGs would be ineffective. Subnet delegation is for specific Azure services, not private endpoints. Associating a route table primarily controls traffic routing, not access control. A NAT gateway is for outbound internet connectivity, not internal access control.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed