You have a storage account named account1. You will upload VM disk files from an on-premises network with public IP range 131.107.1.0/24 and then attach those disks to VM1 in VNet1 (192.168.0.0/24). Configure account1 so you can upload the disks, attach them to VM1, and block all other access. Which two actions should you take on account1?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Networking blade of account1, select Selected networks., From the Networking blade of account1, add the 131.107.1.0/24 IP address range..
Why this is the answer
To restrict access to account1 while allowing specific sources, you must first enable "Selected networks" under the Networking blade. This setting ensures that only explicitly allowed networks or IP ranges can access the storage account. Then, to enable uploads from the on-premises network, you need to add its public IP range, 131.107.1.0/24, to the allowed IP address ranges. The VM in VNet1 will access the storage account via Azure's internal network, which is implicitly allowed when "Selected networks" is chosen, so adding VNet1 explicitly is unnecessary. "Allow trusted Microsoft services" is not required here as direct IP and VNet access is sufficient and more restrictive. Adding a service endpoint to VNet1 would be part of a different configuration, not directly related to enabling this specific access pattern for the storage account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed