AZ-700 Private Link and Service Endpoints Flashcards
6 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 AZ-700 Private Link and Service Endpoints flashcards as text
What do service endpoint policies allow you to do?
Answer: Restrict VNet service endpoint access to specific Azure Storage accounts
Service endpoint policies let you filter outbound VNet traffic to Azure Storage, allowing access only to specific storage accounts rather than all accounts.
By default, what is the state of network policies for private endpoints on a subnet?
Answer: Disabled
Network policies (such as NSG and UDR support) for private endpoints are disabled by default on subnets and must be explicitly enabled.
Which type of load balancer is required to create an Azure Private Link service exposing your own application?
Answer: Standard Internal Load Balancer
Azure Private Link service requires a Standard tier internal load balancer as the frontend to expose your service privately to consumers.
Can private endpoints be used to access services across different Azure Active Directory tenants?
Answer: Yes, with manual approval by the resource owner
Cross-tenant private endpoint connections are supported but require manual approval from the resource owner in the other tenant.
What does Azure Private Link Center provide?
Answer: Centralized monitoring and management for private endpoints and Private Link services
Azure Private Link Center is a portal hub that gives you a unified view for monitoring, managing, and auditing all private endpoints and Private Link services in your subscription.
Which statement about application security groups (ASGs) and private endpoints is correct?
Answer: ASGs can be applied to private endpoint NICs to simplify NSG rules
Once network policies are enabled on a subnet, ASGs can be associated with private endpoint NICs, allowing you to reference them in NSG rules instead of individual IPs.