Site1 (on-premises) is connected to VNet1 via a Site-to-Site VPN. You have a storage account named storage1 in the Azure subscription. You want servers in Site1 to connect to storage1 over the S2S VPN with the least administrative effort. What should you create in VNet1?
Choose an answer
Tap an option to check your answer.
Correct answer: a private endpoint.
Why this is the answer
A private endpoint is the correct choice because it creates a private IP address for storage1 within VNet1, allowing servers in Site1 to access storage1 directly over the S2S VPN tunnel. This keeps traffic within the Microsoft backbone and your private network, enhancing security and performance with minimal administrative overhead. An Azure Application Gateway is a Layer 7 load balancer and wouldn't facilitate private access to a storage account over a VPN. An Azure Private Link service is used to expose your own service privately to other VNets or on-premises networks, not to access Azure services. A service endpoint allows VNet resources to access Azure services over an optimized route within the Azure backbone, but it doesn't route traffic over a VPN tunnel from on-premises and doesn't provide a private IP within the VNet for the service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed