A water-quality archive storage account is reachable from any Internet IP. Which resource firewall change should the security engineer make first?
Select an answer to reveal the explanation.
Short Explanation
Storage’s public front door isn’t fixed with an NSG sticker. Flip the account’s public network access to selected networks—or Disabled when Private Endpoint owns the path.
Full Explanation
Azure Storage exposes a resource-level network firewall. Setting public network access to selected virtual networks and IP addresses (or Disabled when Private Endpoint is the intended path) restricts who can reach the data plane over the public endpoint. Storage does not use an NSG on a PaaS public VIP the way VMs do. Key rotation and soft delete address credentials and data retention, not the public network exposure setting.