How Do You Keep VM1-to-Storage1 Traffic Off the Internet?
You have an Azure subscription that contains the resources shown in the following table. You need to ensure that data transfers between storage1 and VM1 do NOT traverse the internet What should you configure for storage1? - 
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests whether you know that Azure Private Link / private endpoints are the mechanism that keeps PaaS storage traffic on the Microsoft backbone, while the trap is confusing network routing with authorization controls such as SAS tokens or firewall public-network settings.
This AZ-104 question asks how to make traffic between an Azure VM and an Azure Storage account avoid the public internet. The page establishes that the correct configuration is a private endpoint on storage1, which places a private IP from VM1's virtual network in front of the storage service.
Many learners pick 'Public network access in the Firewalls and virtual networks settings', assuming that restricting the firewall to the VM's subnet stops internet traversal. It does not — firewall rules filter who can connect over the public endpoint, but the traffic still leaves the VNet to the storage account's public IP address.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A private endpoint gives storage1 a private IP address inside the virtual network (or a peered/connected VNet), so the VM resolves the storage account's blob/file/queue/table endpoint to that private IP and the traffic rides the VNet and Microsoft backbone instead of the public internet. That is exactly the requirement: data transfers between storage1 and VM1 must not traverse the internet. Private endpoints are part of Azure Private Link and are the only option listed that changes the network path rather than the authorization or filtering behaviour. Yumperboy's comment captures the doctrine well: a private endpoint uses "a private IP address from your VNet, effectively bringing the service into your VNet". Because the reference answer is B and every recorded vote is B, the answer key, the community and Microsoft's own Private Link guidance all agree here.Why the Other Options Are Wrong
Data protection (A) is a set of storage features such as soft delete, versioning, and immutable blobs — it governs durability and recoverability of data, not the route packets take, so it has no effect on internet traversal. A shared access signature (D) is a delegated authorization token that grants time-limited access to storage resources; traffic signed with a SAS still travels over the storage account's public endpoint. Public network access in the Firewalls and virtual networks settings (C) can restrict the storage account to selected VNets and IP ranges, but it does not pull the service into the VNet: allowed clients still connect to the public endpoint and the packets still cross the internet path unless a private endpoint or service endpoint is separately configured. Restricting the firewall without a private endpoint therefore fails the 'do NOT traverse the internet' test.Community Comment Notes
The comment thread is unusually one-sided: as Yumperboy and SkyZeroZx both explain, the private endpoint gives storage1 a private IP from the VNet and keeps VM-to-storage traffic on the virtual network, and "all the traffic from VM1 to storage1 travels across the Microsoft backbone network without going out to the public internet". testtaker09 reports seeing this item in the exam on 17/06/2024, and RajeshwaranM grumbles that it is a "Repeated questions" item — useful signal that this scenario shows up often. Peachu200 simply states the "correct Amswer:B", and Mysystemad and edurakhan confirm B as well. No commenter argues for A, C, or D, so there is no credible competing rationale to weigh against the Private Link reasoning.Official Reference
Exam Strategy
When a stem says traffic must 'not traverse the internet' between a VM and a PaaS service, scan the options for 'private endpoint' (or service endpoint) before anything about firewalls, SAS, or encryption. Authorization answers (SAS, keys, RBAC) and data-protection answers (soft delete, versioning) can never change the network path, so they are distractors by construction.
Frequently Asked Questions
Why isn't restricting public network access in Firewalls and virtual networks enough?
That setting only filters which VNets and IP addresses may reach the storage account's public endpoint. Allowed traffic still leaves the VNet for the public endpoint, so it can traverse the internet.
Does a SAS token keep VM1-to-storage1 traffic off the internet?
No. A shared access signature is a time-limited authorization credential; it grants access but does not change the network path, so packets still use the storage account's public endpoint.
What exactly does a private endpoint create for storage1?
It assigns a private IP from your VNet to the storage service, and name resolution returns that private IP so VM1 talks to storage1 entirely over the virtual network and Microsoft backbone.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →