Azure Administrator (AZ-104) · Free practice question 9 of 12
NAT gateway for predictable outbound IP
VMs at Hartfield Legal have no public IP addresses and are placed in the snet-batch subnet. A partner requires all outbound internet connections from these VMs to come from a single, predictable public IP address that it can add to an allow list. What should you configure?
- A.An internal load balancer with a private frontend IP
- B.A private endpoint on snet-batch
- C.A service endpoint for Microsoft.Web on snet-batch
- D.A NAT gateway with a static public IP address associated with snet-batch
Show answer and explanation
Correct answer: D. A NAT gateway with a static public IP address associated with snet-batch
Why: A NAT gateway associated with a subnet provides outbound internet connectivity for its VMs by translating their traffic to the NAT gateway's public IP addresses or prefixes, giving the partner a fixed source address. An internal load balancer has no public address. Private and service endpoints provide access to Azure services and do not give outbound internet traffic a fixed public IP.
More free Azure Administrator (AZ-104) questions
- Elevate Global Administrator access
- Registering a resource provider
- Static website hosting in Storage
- Secure transfer required setting
- Spot VMs for interruptible workloads
- Proximity placement groups
- App Service Always On
- Regional service tags in NSG rules
- Azure DNS alias record at apex
- Metric alerts with dynamic thresholds
- Service Health alerts