You have storage1 and VM1. VM1 is on VNet1 (one subnet) and uses Azure DNS. To ensure VM1 connects to storage1 using a private IP address with minimal administrative effort, what should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: For storage1, create a new private endpoint..
Why this is the answer
Creating a new private endpoint for storage1 is the correct solution. A private endpoint creates a private IP address within VNet1 for storage1, allowing VM1 to connect directly over the Azure backbone network instead of the public internet. This ensures secure communication using a private IP and minimizes administrative effort as it integrates seamlessly with Azure DNS. Disabling public network access for storage1 would prevent public access but wouldn't provide a private connection for VM1; it would simply block all connections if a private endpoint isn't configured. Creating a new subnet on VNet1 is unnecessary as the existing subnet can host the private endpoint. Creating an Azure Private DNS zone is often a subsequent step to ensure proper name resolution for the private endpoint, but the private endpoint itself is the primary component for establishing the private connection.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed