Private Endpoints and Private Link Flashcards
6 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Private Endpoints and Private Link flashcards as text
What DNS change is required to ensure Azure resources resolve a Private Endpoint's private IP instead of the service's public IP?
Answer: Create a Private DNS Zone for the service and link it to the VNet
Creating a Private DNS Zone (e.g., privatelink.blob.core.windows.net) and linking it to the VNet overrides public DNS resolution with the private endpoint's IP.
How does a Private Endpoint affect network security for an Azure PaaS service?
Answer: It allows the service to be accessed from the private IP and can be used alongside firewall rules to disable public access
Private Endpoints provide a private IP path and can be combined with disabling public network access on the service to ensure all traffic is private.
Which feature allows you to use a single Private Endpoint to access multiple services behind the same Private Link Service?
Answer: Sub-resources (group IDs) allow targeting specific service sub-components
Some services expose multiple sub-resources (group IDs); you create separate Private Endpoints for each sub-resource (e.g., blob vs. file for Storage Account).
What happens to a Private Endpoint if the linked Azure resource (e.g., storage account) is deleted?
Answer: The Private Endpoint remains and shows a 'disconnected' state
When the underlying resource is deleted, the associated Private Endpoint enters a 'disconnected' state and must be manually deleted.
Which Azure tool can you use to audit all Private Endpoint connections and their approval status across your subscription?
Answer: The Private Link Center in the Azure portal
The Azure Private Link Center provides a centralized view of all Private Endpoints and Private Link Services, including connection approval status.
Can a Private Endpoint be accessed from an on-premises network connected via ExpressRoute or VPN?
Answer: Yes — on-premises clients can reach Private Endpoints via ExpressRoute or VPN with proper DNS forwarding
On-premises clients can access Private Endpoints over ExpressRoute or VPN; DNS must be configured to resolve the privatelink FQDN to the private IP.