Fabrikam has a storage account named fabrikamfiles in rg-storage-eastus and creates a Private Endpoint for the blob service in a spoke VNet. The networking team wants DNS resolution within the spoke VNet to resolve fabrikamfiles.blob.core.windows.net to the private IP of the Private Endpoint. Which Private DNS zone name should they create and link to the VNet so the Auto-registered record is created correctly?
Choose an answer
Tap an option to check your answer.
Correct answer: privatelink.blob.core.windows.net.
Why this is the answer
The correct Private DNS zone name for Azure Storage (blob service) Private Endpoints is privatelink.blob.core.windows.net. When this specific zone is linked to the VNet where the Private Endpoint resides, Azure automatically creates an A record mapping the storage account's FQDN (e.g., fabrikamfiles.blob.core.windows.net) to the Private Endpoint's IP address. This ensures that DNS queries originating from within the VNet resolve to the private IP, bypassing public DNS. fabrikamfiles.privatelink.core.windows.net is incorrect because it includes the storage account name, which is not part of the standard Private DNS zone naming convention for auto-registration. privatelink.core.windows.net is too generic and doesn't specify the service type (blob storage). blob.privatelink.core.windows.net is also incorrect as the standard format places privatelink before the service type.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed