VNet1 has a subnet named Subnet1. You must ensure that the resources connected to Subnet1 can access only storage1 and storage3 while minimizing administrative overhead. Which configuration should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: a service endpoint policy.
Why this is the answer
A service endpoint policy allows you to filter egress traffic from a virtual network to Azure services, specifying which storage accounts are accessible. This directly addresses the requirement to allow access only to storage1 and storage3 while minimizing administrative overhead compared to managing individual network security group rules for each storage account. An application security group (ASG) groups VMs and defines network security rules based on those groups, but it doesn't control access to specific Azure service instances like storage accounts. Azure Private Link provides private connectivity to Azure services over a private IP address, but it's for inbound access to the VNet or for connecting to specific service instances privately, not for filtering outbound access to specific instances of a public service. A service tag represents a group of IP address prefixes for a given Azure service, but it doesn't allow granular control over specific instances of that service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed