Minimum Azure Service Endpoints for Peered VNets

Design and implement service endpoints
Answer Correct answer: A — Create 2 service endpoints (one for Microsoft.Storage and one for Microsoft.Sql) to cover all resources across the peered VNets.

You have an Azure subscription that contains the resources shown in the following table. You need to ensure that the virtual machines can access storage1, storage2, and DB1 by using service endpoints. What is the minimum number of service endpoints you should create? - image

  1. 2 Correct Answer
  2. 3
  3. 4
  4. 12

Community Votes

A
53%
C
47%

53% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding that a single service endpoint per resource type applies across all subnets within a VNet and its peers, avoiding redundant configurations.

Determines the minimum number of service endpoints needed to connect peered virtual networks to Azure storage and SQL resources, establishing that two endpoints are sufficient.

Most learners select C (4) because they incorrectly assume that each Virtual Network requires separate service endpoint configurations for every resource type.

Community Discussion (5 comments)

alinuxguru70 👍 6 Selected: A
2 Both storage accounts require a single service endpoint for "Microsoft.Storage." The Azure SQL Database requires a service endpoint for "Microsoft.Sql."
Abilash2605 👍 5 Selected: C
We have Two Vnets. we can only link one service endpoint per Vnet. we need one service endpoint for storage and one service endpoint for Microsoft.SQL. for two vnets we deploy 4 Service endpoint.
Saba53 👍 1 Selected: A
2 Should be correct
bobothewiseman 👍 1 Selected: A
VNet1 and VNet2 are peered, subnets in one VNet can access resources in the other VNet via the same service endpoint, single service endpoint for Azure Storage is sufficient to allow all subnets in both VNets to access storage1 and storage2. single service endpoint for Azure SQL is sufficient to allow all subnets in both VNets to access DB1.
juancarlosdlar 👍 2 Selected: C
https://learn.microsoft.com/en-us/azure/virtual-network/vnet-integration-for-azure-services#compare-private-endpoints-and-service-endpoints

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is A because service endpoints are configured at the subnet level to secure traffic to specific Azure services. Since the two Virtual Networks (VNet1 and VNet2) are peered, they share network identity and reachability. You only need one service endpoint for 'Microsoft.Storage' on a subnet in VNet1 and one for 'Microsoft.Sql' on a subnet in VNet1 (or VNet2). These endpoints allow all subnets in both VNets to access the respective resources securely without needing individual endpoints for each VNet or each storage account.

Why the Other Options Are Wrong

Option B (3) is incorrect because it implies a third distinct endpoint type is needed, but there are only two resource types (Storage and SQL). Option C (4) is the most common distractor; it assumes you must create one endpoint per VNet per resource type (2 VNets × 2 Resources = 4), which ignores the scope of service endpoints across peering. Option D (12) likely results from counting every subnet individually, which is unnecessary as endpoints apply to the subnet's traffic to the service.

Community Comment Notes

User alinuxguru70 correctly identifies that both storage accounts require a single endpoint for 'Microsoft.Storage' and the database requires one for 'Microsoft.Sql'. User bobothewiseman reinforces this by noting that peering allows subnets in one VNet to access resources in the other via the same endpoint. Conversely, user Abilash2605 argues for 4 endpoints, stating "We have Two Vnets. we can only link one service endpoint per Vnet," which reflects the common misconception that endpoints do not traverse peering boundaries.

Official Reference

Exam Strategy

When configuring service endpoints for peered VNets, always count unique Azure service types (e.g., Storage, SQL) rather than the number of VNets or subnets. One endpoint per service type is sufficient for all connected VNets.

Frequently Asked Questions

Do I need separate service endpoints for each storage account?

No. A single service endpoint for 'Microsoft.Storage' secures traffic to all storage accounts accessible from that subnet.

Does peering automatically enable service endpoints?

No. Peering provides connectivity, but you must still explicitly enable the service endpoint policy on the subnet to restrict access and optimize routing.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide