Private Endpoint UDR Routing Prerequisite
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a subnet named Subnet1. You plan to add a private endpoint to Subnet. You need to ensure that you can route traffic between the private endpoint and the Azure Private Link service by using a user-defined route. What should you do first on Subnet1?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the prerequisite for applying security policies to private endpoints: unlike standard subnets, private endpoints require 'Network Policies' to be enabled rather than delegation or service endpoints.
This question addresses the specific subnet configuration required to apply User-Defined Routes (UDRs) and Network Security Groups to an Azure Private Endpoint. It establishes that network policies must be explicitly enabled on the subnet before the private endpoint is created.
Candidates often select Enable Delegation because it is a common requirement for other Azure services like App Service Environments or Container Instances, but delegation prevents the subnet from being used by Private Endpoints.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To route traffic between a private endpoint and the Azure Private Link service using a user-defined route (UDR), you must first enable network policy on the subnet. By default, network policies are disabled for subnets containing private endpoints to allow the underlying infrastructure to manage the endpoint's lifecycle. Enabling this policy allows Azure to enforce UDRs and NSGs on the private endpoint's network interface.Why the Other Options Are Wrong
Enabling delegation (Option B) assigns control of the subnet to a specific Azure resource provider (like Microsoft.Web or Microsoft.App). A subnet can only have one delegation; if it is delegated to another service, it cannot host a private endpoint. Creating a service endpoint (Option C) exposes resources over the Azure backbone but does not enable UDR support on private endpoints. Provisioning a Standard Load Balancer (Option D) is unrelated to the internal routing requirements of a private endpoint.Community Comment Notes
Several community members correctly identified that delegation is incompatible with private endpoints. One user noted that "Delegation Can't be used with a private endpoint if the subnet is delegated," citing official documentation. Another learner confirmed that enabling network policy is the necessary step to utilize policies like UDRs, stating "To use network policies like user-defined routes... network policies must be enabled."Official Reference
Exam Strategy
When dealing with Private Endpoints, always check if the question involves security policies (NSG/UDR). If so, the answer is typically 'Enable Network Policy.' Remember that Private Endpoints do not use Subnet Delegation.
Frequently Asked Questions
Why can't I use delegation for a private endpoint subnet?
Delegation assigns subnet control to a specific Azure service provider. Since Private Endpoints are managed by the Virtual Network infrastructure, they conflict with delegation.
Do I need a load balancer for private endpoint routing?
No. Private endpoints rely on the Azure backbone and UDRs for routing. A load balancer is used for inbound/outbound traffic distribution, not internal endpoint routing.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →