Azure Private Link Service Configuration for VM Access

Design and implement Azure Private Link service and Azure private endpoints
Answer Correct answer: B — Configure an Azure Standard Load Balancer in Sub1 to provide the frontend IP configuration required for the Private Link Service.

You have two Azure subscriptions named Sub1 and Sub2. Sub1 contains a virtual machine named VM1. You plan to make VM1 available to the resources in Sub2 by using Azure Private Link. You need to ensure that the private link service can be configured to provide access to VM1. What should you configure in Sub1 first?

  1. an Azure Private DNS zone
  2. an Azure load balancer Correct Answer
  3. a service endpoint
  4. a private endpoint

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the dependency chain for exposing a VM via Private Link: you must configure a Standard Load Balancer first to create the Private Link Service resource.

This page explains how to expose an Azure Virtual Machine to another subscription using Azure Private Link, focusing on the prerequisite configuration of a Standard Load Balancer. It establishes that a load balancer is required before creating the Private Link Service.

Most learners incorrectly select 'Private Endpoint' (D), confusing the consumer side (subscriber) with the provider side (VM owner). They fail to realize that a VM cannot be directly attached to a Private Endpoint; it needs a frontend IP configuration via a Load Balancer or NAT Gateway.

Community Discussion (4 comments)

manhattan 👍 1 Selected: B
Can't be D, VM is not supported as private endpoint resource. it's B even if it doesn't make so much sense, if it's in the same tenant peering or routes would have been a better solution. I think it's just a way to test you know about private link service
MHy2k 👍 1 Selected: D
D: A private endpoint, is a network interface that connects you privately and securely to a service powered by Azure Private Link.
gaurav4101 👍 2 Selected: B
Configure 1. Standard LB (Provider side) 2. Enable private link service and attach to front end ip of LB(Provider side) 3.Shared private service id with user which can be uri (Provider side) 4. Create a private endpoint using private service id in step 3 (Subscriber side) 5. approve the request (Provider side) 6. Configure DNS record pointing to private ip address of endpoint (Subscriber side) 7. connection approved/rejected(Subscriber side) ============= https://learn.microsoft.com/en-us/azure/private-link/private-link-service-overview
alinuxguru70 👍 3 Selected: B
You need to create the load balancer first https://learn.microsoft.com/en-us/azure/private-link/private-link-service-overview

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To make a virtual machine available via Azure Private Link, you must first create a Private Link Service in the provider's subscription (Sub1). A Private Link Service requires a frontend IP configuration, which is provided by an Azure Standard Load Balancer. Therefore, configuring the load balancer is the necessary first step. Without the load balancer, you cannot define the backend pool or the frontend IP that the Private Link Service will expose.

Why the Other Options Are Wrong

Option D (Private Endpoint) is incorrect because a private endpoint is created in the consumer subscription (Sub2) to connect to the service; it is not configured in Sub1 first. Option A (Private DNS zone) is typically associated with the consumer side or manual resolution, not the initial infrastructure setup in the provider side. Option C (Service Endpoint) provides access over the Microsoft backbone but does not use Private Link and is not the correct mechanism for this scenario.

Community Comment Notes

Community consensus strongly supports Option B. One user noted, "You need to create the load balancer first," citing official documentation. Another commenter clarified the workflow: "Configure 1. Standard LB (Provider side)... Enable private link service." A dissenting vote for D was corrected by noting, "VM is not supported as private endpoint resource," confirming that the VM must go through a load balancer or similar frontend.

Official Reference

Exam Strategy

Always distinguish between the 'Provider' (resource owner) and 'Consumer' (access seeker) roles in Private Link questions. If the question asks what to configure in the subscription containing the VM/service, look for the Load Balancer or NAT Gateway required to host the Private Link Service.

Frequently Asked Questions

Why can't I attach the VM directly to a Private Endpoint?

A Private Endpoint connects to a specific Azure service resource. For a VM, you must expose it via a Private Link Service, which requires a Load Balancer frontend IP configuration.

Do I need a Public IP for the Load Balancer?

No, when used with Private Link, the Standard Load Balancer should be configured without a public IP address to ensure traffic remains within the Azure backbone.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide