A service endpoint policy is configured with these settings: associated subnets = Subnet1, service = Microsoft.Storage, scope = Single account, resource = storage1. Given those settings, which storage resources can a VM located in Subnet1 (VM1) access?
Choose an answer
Tap an option to check your answer.
Correct answer: storage1 in the East US region and its replica in the paired region.
Why this is the answer
A service endpoint policy allows you to filter network traffic to specific Azure storage accounts over service endpoints. The policy in question is configured to allow access only to storage1 with a scope of Single account. This means that VM1 in Subnet1 can access storage1. Azure Storage accounts are geo-redundant by default, meaning data is replicated to a paired region for disaster recovery. Therefore, access to storage1 implicitly includes access to its replica in the paired region to maintain data availability and consistency. The other options are incorrect because the policy explicitly limits access to storage1 only, excluding other storage accounts like storage2, and the policy does not restrict access based on region for the specified account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed