Service Endpoints and Endpoint Policies
This topic covers service endpoints, service endpoint policies, subnet access, storage firewall integration, private endpoint comparisons, and access troubleshooting.
How to study for AZ-700
Treat each AZ-700 item as a traffic-path problem: trace source, destination, DNS, route, next hop, load balancing, private access, and filtering before choosing.
Core concepts
Concept 1
Service Endpoints and Endpoint Policies questions test Azure networking design and troubleshooting choices rather than memorized portal paths.
Exam cue: Identify the traffic path, scope, protocol, name resolution behavior, next hop, inspection point, and security control.
Concept 2
The best answer traces traffic from source to destination through addressing, DNS, routing, security, connectivity, and delivery controls.
Exam cue: Choose the Azure networking service that fits reachability, availability, latency, scale, and security requirements.
Concept 3
Eliminate answers that ignore effective routes, name resolution, subnet constraints, private DNS, health probes, or network security boundaries.
Exam cue: Prefer least exposure, private access, validated routes, monitored health, and explicit security policy.
Risk pitfalls and guardrails
Confusing DNS resolution with routing or security filtering.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Opening public access when Private Link, VPN, ExpressRoute, or service endpoints meet the requirement.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Choosing load balancing without matching layer 4, layer 7, regional, global, or DNS-routing behavior.
Guardrail: Avoid answers that confuse DNS with routing, service endpoints with private endpoints, NSGs with firewalls, or layer 4 and layer 7 load balancing.
Memory anchors
Service Endpoint
A service endpoint extends a VNet private address identity to a supported Azure service.
Endpoint Policy
A service endpoint policy restricts access from a subnet to specific supported service resources.
Storage Firewall
A storage firewall can allow selected networks, IP ranges, trusted services, or private endpoints.
Subnet Association
Service endpoints are enabled on subnets for selected Azure services.
Service Endpoint Route
Service endpoint traffic uses optimized routes to the Azure service over the Microsoft backbone.
Private Endpoint Difference
A private endpoint gives a service a private IP in the VNet, while a service endpoint preserves the public endpoint.
Resource Instance Rule
A resource instance rule can allow selected Azure resource instances to access supported storage accounts.
Trusted Services
Trusted services can access selected Azure services when explicitly allowed.
Access Troubleshooting
Access troubleshooting checks firewall, endpoint type, DNS, subnet, identity, and service support.
Least Exposure
Least exposure chooses the narrowest endpoint and firewall configuration that satisfies connectivity requirements.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A subnet uses a Microsoft.Storage service endpoint. What changes for traffic sent to an allowed storage account?
After enabling a service endpoint on a subnet, a storage account still accepts clients from the Internet. What is missing?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
