You need to provide access to storage2 and meet the stated PaaS networking and business requirements. Which connectivity method should you choose?
Choose an answer
Tap an option to check your answer.
Correct answer: a private endpoint.
Why this is the answer
A private endpoint is the correct choice because it provides secure, private connectivity to Azure PaaS services like Azure Storage over a private IP address within your virtual network. This ensures that traffic to storage2 traverses the Microsoft backbone network and is not exposed to the public internet, fulfilling the PaaS networking and business requirements for secure and private access. Azure Firewall is a network security service that filters traffic to and from resources, but it doesn't provide private connectivity to PaaS services. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, primarily for public-facing web applications, not private PaaS access. A service endpoint extends your virtual network's identity to Azure services over a direct connection, but traffic still uses public IP addresses and traverses the public internet, albeit over an optimized route, which doesn't meet the "private" access requirement as fully as a private endpoint.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed