Which option should you use to stop traffic from an Azure virtual network being routed to an Azure Storage account over the internet?
Choose an answer
Tap an option to check your answer.
Correct answer: a service endpoint.
Why this is the answer
A service endpoint allows you to secure Azure service resources to only your virtual network, extending your virtual network's identity to the Azure service. This routes traffic directly from your virtual network to the Azure service over the Azure backbone network, bypassing the public internet. This ensures that traffic to Azure Storage from your virtual network does not traverse the internet. An NSG filters network traffic to and from Azure resources in an Azure virtual network, but it cannot prevent traffic from being routed over the internet if the destination is a public endpoint. A public endpoint is the default way to access most Azure services over the internet. Azure VPN Gateway connects your on-premises networks to Azure virtual networks over a secure tunnel, but it doesn't control how traffic from an Azure virtual network reaches Azure services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed