You have an Azure subscription with a virtual network named VNet1 that contains a subnet called Subnet1. You plan to create a private endpoint in Subnet1. To be able to route traffic between the private endpoint and the Azure Private Link service using a user-defined route (UDR), what must you do first on Subnet1?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable delegation..
Why this is the answer
To use a user-defined route (UDR) with a private endpoint in a subnet, you must enable subnet delegation. Delegation allows the subnet to host specific Azure services, such as Private Link, and ensures proper routing behavior when UDRs are present. Without delegation, UDRs might override the Private Link's internal routing, preventing connectivity. Enabling network policy is for Network Security Groups (NSGs) and User-Defined Routes (UDRs) to apply to private endpoints within the subnet, but it doesn't enable the fundamental routing mechanism for Private Link with UDRs. Creating a service endpoint is for accessing Azure services directly over the Azure backbone, not for private endpoints. Provisioning a Standard Azure load balancer is unrelated to the requirement of enabling UDRs for private endpoints.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed