A storage account must accept writes from an Azure Backup vault without opening the Internet to all networks. What should the security engineer use on the storage firewall?
Select an answer to reveal the explanation.
Short Explanation
Backup needs in without inviting the whole Internet. Keep selected networks and flip the trusted Azure services exception—resource group co-location isn’t a firewall free pass.
Full Explanation
When a storage account firewall limits public access to selected networks, Azure Backup and other documented Microsoft services can still be allowed through the trusted Azure services exception or supported resource-instance rules. Enabling access from all networks removes that protection. Co-locating resources in a resource group does not bypass network rules. SAS credentials authorize requests; they do not replace a correctly scoped resource firewall.