To let VM1 reach a new Azure SQL Managed Instance, create a dedicated delegated subnet, associate an NSG, and attach a route table
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a single subnet. The subscription contains a virtual machine named VM1 that is connected to VNet1. You plan to deploy an Azure SQL managed instance named SQL1. You need to ensure that VM1 can access SQL1. Which three components should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Community Votes
100% of anonymous learners picked answer ADE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
SQL Managed Instance networking has three mandatory building blocks: a delegated subnet, an NSG on that subnet, and a route table on that subnet. A VNet gateway and network security perimeter are not required for basic VM-to-MI connectivity.
An Azure SQL Managed Instance requires its own dedicated subnet delegated to Microsoft.Sql/managedInstances. That subnet must have a network security group to filter traffic and a user-defined route table to direct traffic (including the route to the managed instance's private endpoint), so VM1 on the same VNet can connect.
Candidates add a VNet gateway or network security perimeter, but those are not part of the core SQL MI subnet requirements; the three required components are the subnet, NSG, and route table.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure SQL Managed Instance must be deployed into a dedicated subnet delegated to the SQL Managed Instance service. Microsoft's connectivity architecture requires that subnet to have an associated network security group (to control traffic) and an associated route table (to route traffic, including the mandatory route to the managed instance). Together with VM1 on the same VNet, these three components enable access. (Options A, D, E)Why the Other Options Are Wrong
- Option B (Network security perimeter) is a newer boundary control not required for the basic VM-to-MI connectivity described.
- Option C (Virtual network gateway) is needed only for on-premises/VPN cross-connectivity, not for VM1 (already in the VNet) to reach the managed instance.