An Azure SQL logical server named SQL1 and a virtual machine VM1 (which uses only a private IP) exist. The firewall and virtual network settings for SQL1 are configured as shown. To allow VM1 to connect to SQL1 while adhering to the principle of least privilege, what should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Add an existing virtual network..
Why this is the answer
To allow VM1 to connect to SQL1 while adhering to the principle of least privilege, you should add an existing virtual network. This option allows you to specify the virtual network and subnet where VM1 resides, granting access only from that specific private network. Setting the Connection Policy to Proxy is irrelevant to network access control; it affects how clients connect to the database. Setting "Allow Azure services and resources to access this server" to Yes would grant access to all Azure services, which violates the principle of least privilege as it's too broad. Creating a new firewall rule would typically involve specifying public IP addresses, which isn't suitable for VM1 since it only uses a private IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed