Your Azure subscription contains a storage account named storage1 that is deployed in the US East region and currently uses locally-redundant storage (LRS). storage1 has a Microsoft.Storage service endpoint. You changed the redundancy for storage1 to Read-access geo-redundant storage (RA-GRS). You must ensure the contents of storage1 can be accessed via a service endpoint in the paired region while minimizing administrative effort. What should you do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a service endpoint policy..
Why this is the answer
Creating a service endpoint policy is the correct first step because it allows you to filter network traffic to Azure services, specifying which storage accounts are allowed. When you change storage1's redundancy to RA-GRS, a read-only secondary endpoint is created in the paired region (e.g., US West for US East). To ensure this new endpoint is accessible via a service endpoint, you need to update or create a policy that includes the paired region's endpoint. Object replication rules are for replicating blobs between storage accounts, not for managing service endpoint access to a geo-redundant secondary. Deleting the existing service endpoint would disrupt current access and isn't necessary. "Secure transfer required" enhances security by enforcing HTTPS but doesn't address service endpoint access to the paired region.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed