You have VM1 and VM2 that must be allowed to connect only to storage1 and must be prevented from accessing any other storage accounts. Storage1 must still be reachable from the internet. Which solution should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: a service endpoint policy.
Why this is the answer
A service endpoint policy allows you to filter egress traffic from a virtual network to Azure Storage, specifying which storage accounts are allowed. This ensures VM1 and VM2 can only access storage1 while blocking other storage accounts. Since service endpoints use public IP addresses, storage1 remains accessible from the internet. An NSG controls network traffic to and from network interfaces or subnets but cannot restrict access to specific storage accounts within a service endpoint. A private link creates a private connection to Azure services, making them accessible privately, but doesn't restrict access to specific accounts. A private endpoint is a network interface that connects you privately and securely to a service powered by Azure Private Link, also not providing the granular control needed for specific storage account access while maintaining internet reachability.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed