Private Endpoints and Private Link Flashcards
6 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Private Endpoints and Private Link flashcards as text
What is the difference between a Service Endpoint and a Private Endpoint for securing access to Azure Storage?
Answer: Service Endpoints extend VNet identity to Storage over the backbone but Storage retains a public IP; Private Endpoints give Storage a private IP in your VNet
Service Endpoints route traffic over the backbone but the service still has a public IP; Private Endpoints assign a private IP in your VNet, enabling fully private access.
Which policy must be enabled on a subnet to apply NSG rules and UDRs to Private Endpoint traffic?
Answer: PrivateEndpointNetworkPolicies = Enabled
Setting PrivateEndpointNetworkPolicies to 'Enabled' on a subnet allows NSGs and UDRs to be applied to traffic destined for private endpoints in that subnet.
What is an Azure Private Link Service alias used for?
Answer: Is a globally unique name used by consumers to request a connection to your Private Link Service
The Private Link Service alias is a globally unique string that consumers use to identify and request a connection to your service without needing full resource IDs.
How many private IPs does a single Private Endpoint consume from the subnet's address space?
Answer: One private IP per Private Endpoint
Each Private Endpoint consumes exactly one private IP address from the subnet, regardless of the number of ports or protocols the service uses.
When deploying Private Endpoints at scale across hundreds of VNets, which DNS architecture is recommended by Microsoft?
Answer: Centralized Private DNS Zones in a hub VNet, linked to all spoke VNets
Microsoft recommends centralized Private DNS Zones in a hub VNet with links to all spoke VNets to avoid zone proliferation and ensure consistent resolution.
Which Azure networking feature allows you to restrict which specific resources (not just subnets) can access an Azure Storage account via Service Endpoints?
Answer: Service Endpoint Policies
Service Endpoint Policies let you specify exact Azure Storage accounts (or other resources) that a subnet can reach via Service Endpoints, providing resource-level granularity.