Which configuration can help ensure that storage accounts restrict network access?

Disable ads (and more) with a premium pass for a one time $4.99 payment

Master the Microsoft Cybersecurity Architect Expert exam with our comprehensive SC-100 quiz. Learn with detailed questions, explanations, and get exam-ready with expert insights!

To ensure that storage accounts restrict network access effectively, implementing Virtual Network (VNet) rules is essential. VNet rules allow you to configure your storage account to only accept traffic from specified virtual networks and subnets within Azure. This means that resources within those defined VNets can access the storage account, while all other traffic is denied, providing a strong security posture.

VNet rules are particularly beneficial in scenarios where sensitive data is stored, and organizations need to control which networks and applications can access that data. By leveraging VNet integration, companies can mitigate the risks associated with unauthorized access and potential data breaches.

The other options do not enhance network access restrictions: enabling public access would expose the storage account to the internet, allowing unrestricted access from any source. Allowing dynamic IP access contradicts the purpose of restricting access since it opens the account to any IP address that may change over time, making it challenging to manage security. Allowing internet traffic also opens up the storage to all external users, which is not in line with restricting access effectively.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy