Your on-premises network includes a VPN gateway and your Azure subscription contains the resources shown in the table. What should you configure to force VM1-to-storage1 traffic to use the Microsoft backbone?
Choose an answer
Tap an option to check your answer.
Correct answer: Private endpoints.
Why this is the answer
Private endpoints allow services like Storage1 to be accessed privately from your virtual network over the Microsoft backbone, bypassing the public internet and your on-premises VPN gateway. This ensures traffic between VM1 and Storage1 remains within Azure's private network. Network security groups (NSGs) control network traffic flow but don't redirect traffic to the Microsoft backbone; they filter it. Microsoft Entra Application Proxy provides secure remote access to on-premises web applications, not private Azure service connectivity. Azure Virtual WAN simplifies large-scale branch connectivity and routing but isn't the direct mechanism for forcing specific VM-to-service traffic onto the Microsoft backbone for a single storage account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed