You have an Azure Data Lake Storage Gen2 account named storage1 and an Azure Synapse workspace named synapsews1 deployed to a managed virtual network. To allow synapsews1 to access storage1, which networking construct should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: a private endpoint.
Why this is the answer
A private endpoint is the correct choice because it creates a private IP address for storage1 within synapsews1's managed virtual network. This allows secure, private access to the storage account over the Azure backbone, bypassing public internet exposure. Peering connects two virtual networks, but doesn't directly provide private access to a PaaS service like Data Lake Storage Gen2 from a managed VNet. A network security group (NSG) filters network traffic at the subnet or NIC level but doesn't establish private connectivity to a PaaS service. A virtual network gateway is used for cross-premises or VNet-to-VNet connectivity, not for connecting a managed VNet to an Azure PaaS service via a private link.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed