Azure Solutions Architect Expert (AZ-305) · Free practice question 6 of 12
Private Link service for SaaS providers
Fairview Analytics runs a SaaS reporting service behind a Standard Load Balancer in its own Azure subscription. Customers want to reach the service privately from their own virtual networks, without VNet peering and without overlapping address conflicts. What should you recommend that Fairview deploy?
- A.An Azure Private Link service attached to the load balancer, which customers connect to by using private endpoints
- B.VNet peering from each customer virtual network to Fairview's virtual network
- C.A virtual network service endpoint on Fairview's subnet
- D.A site-to-site VPN from each customer to Fairview
Show answer and explanation
Correct answer: A. An Azure Private Link service attached to the load balancer, which customers connect to by using private endpoints
Why: A Private Link service exposes a service behind a Standard Load Balancer so consumers in other tenants can connect through private endpoints in their own virtual networks; traffic uses Microsoft's backbone, and overlapping address spaces are not a problem. Peering and VPNs require non-overlapping addresses and expose wider network access. Service endpoints apply to Azure PaaS services, not to a provider's own service.
More free Azure Solutions Architect Expert (AZ-305) questions
- Pass-through authentication for on-premises policy
- Key Vault key rotation policy
- Queue Storage for large simple backlogs
- API Management multi-region deployment
- Dedicated Host for physical isolation
- Event Hubs Kafka endpoint
- Template specs for versioned templates
- Cosmos DB for Apache Cassandra
- Resource Graph for cross-subscription inventory
- Azure Data Explorer for telemetry analytics
- Performance-based sizing in Azure Migrate