How to Route VM1-to-Storage1 Traffic Across the Microsoft Backbone?

Configure secure access to virtual networks Configure access to storage
Answer Correct answer: B — Configure a private endpoint for storage1 so traffic from VM1 to storage1 travels over the Microsoft backbone via Azure Private Link.

Your on-premises network contains a VPN gateway. You have an Azure subscription that contains the resources shown in the following table. You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network. What should you configure? - image

  1. a network security group (NSG)
  2. private endpoints Correct Answer
  3. Microsoft Entra Application Proxy
  4. Azure Virtual WAN

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The test checks whether you know that private endpoints, not NSGs or Virtual WAN, route PaaS storage traffic over the Microsoft backbone; the trap is confusing traffic filtering or network transit with private connectivity.

This AZ-104 question asks what to configure so all traffic from VM1 to storage1 stays on the Microsoft backbone network. The correct answer is a private endpoint, which uses Azure Private Link to give the storage account a private IP in the virtual network and keeps VM-to-storage traffic off the public internet.

Many learners choose a network security group (NSG) because it is a common Azure security control, but an NSG only filters traffic and cannot change the path that VM1 uses to reach storage1.

Community Discussion (3 comments)

webbrowser 👍 2
The answer is B
behradcld 👍 2 Selected: B
100% correct. I like this question :) Good luck with your exam!
RanPo 👍 3
these kind of question seen all the times, might need to shrink them

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that all traffic from VM1 to storage1 travel across the Microsoft backbone network, which means the traffic must not use the public internet or an on-premises path. A private endpoint creates a private IP address for the Azure Storage account inside the virtual network, and Azure Private Link routes that traffic over the Microsoft global backbone. This satisfies the requirement for VM1 (which is in Azure) to reach storage1 privately, so option B is the correct configuration. The community comment from behradcld states "100% correct" and webbrowser adds "The answer is B," matching the technical analysis.

Why the Other Options Are Wrong

A network security group (NSG) filters traffic but does not change its routing path; it cannot force storage traffic over the Microsoft backbone. Microsoft Entra Application Proxy publishes internal web applications, not Azure Storage endpoints, and is unrelated to VM-to-storage backbone routing. Azure Virtual WAN provides branch-to-branch and branch-to-Azure transit, but it is not the mechanism for privately accessing a PaaS storage account; a private endpoint is the dedicated solution. Therefore, options A, C, and D do not meet the specific requirement.

Community Comment Notes

RanPo noted that this style of question appears frequently and may need condensing, but did not dispute the answer. behradcld called it "100% correct" and said they like the question, confirming B with enthusiasm. webbrowser simply wrote "The answer is B," aligning with the source key and the vote distribution. These comments are consistent with the conclusion that a private endpoint is required.

Official Reference

Exam Strategy

When a question asks for traffic to 'travel across the Microsoft backbone,' think Private Link and private endpoints, not filtering or WAN. Read the source and destination; if one is a PaaS service like Azure Storage, a private endpoint is the expected AZ-104 answer. Eliminate NSGs and Virtual WAN because they address security rules or network transit, not private PaaS connectivity.

Frequently Asked Questions

Why is a network security group (NSG) not enough to route VM1-to-storage1 traffic over the Microsoft backbone?

An NSG only allows or denies traffic; it does not alter the path. A private endpoint is needed to give storage1 a private IP in the VNet and keep traffic on the Microsoft backbone.

Can Azure Virtual WAN force storage1 traffic from VM1 over the Microsoft backbone?

No. Virtual WAN is for hub-and-spoke network transit and branch connectivity, not for privately accessing a PaaS storage account. A private endpoint is the correct service.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide