Your on-premises network includes a VPN gateway. Your Azure subscription contains the resources shown in the table. How do you ensure that all traffic from VM1 to storage1 travels over the Microsoft backbone network?
Choose an answer
Tap an option to check your answer.
Correct answer: Private endpoints.
Why this is the answer
Private endpoints create a private IP address for Azure services within your virtual network, forcing traffic to those services to traverse the Microsoft backbone network rather than the public internet. By configuring a private endpoint for storage1, VM1's traffic to storage1 will remain within Azure's private network. Azure AD Application Proxy is for publishing on-premises web apps securely to external users, not for internal Azure traffic optimization. Network security groups (NSGs) filter network traffic to and from Azure resources but don't dictate the network path (public vs. private backbone). Azure Peering Service optimizes connectivity to Microsoft 365, Dynamics 365, and Azure PaaS services over the public internet, but it doesn't guarantee traffic stays on the Microsoft backbone for private virtual network communication.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed