Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Microsoft > Microsoft Certified: Azure Network Engineer Associate > AZ-700

AZ-700 Designing and Implementing Microsoft Azure Networking Solutions Question and Answers

Question # 4

Your company has an Azure virtual network named Vnet1 that uses an IP address space of 192.168.0.0/20. Vnet1 contains a subnet named Subnet1 that uses an IP address space of 192.168.0.0/24.

You create an IPv6 address range to Vnet1 by using a CIDR suffix of /48.

You need to enable the virtual machines on Subnet1 to communicate with each other by using IPv6 addresses assigned by the company. The solution must minimize the number of additional IPv4 addresses.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 5

You need to meet the network security requirements for the NSG flow logs.

Which type of resource do you need, and how many instances should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 6

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 7

You need to configure GW1 to meet the network security requirements for the P2S VPN users.

Which Tunnel type should you select in the Point-to-site configuration settings of GW1?

A.

IKEv2 and OpenVPN (SSL)

B.

IKEv2

C.

IKEv2 and SSTP (SSL)

D.

OpenVPN (SSL)

E.

SSTP (SSL)

Full Access
Question # 8

You have an on-premises datacenter named Site1 that contains a firewall named FW1. FW1 connects to the internet.

You have an Azure subscription that contains the resources shown in the following table.

You plan to connect Site1 to Hub1 by using a site-to-site connection.

You need to configure the site-to-site connection to FW1.

What should you create in VWAN1?

A.

a VPN site

B.

a virtual network connection

C.

a network virtual appliance (NVA)

D.

a User VPN configuration

Full Access
Question # 9

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.

Full Access
Question # 10

Task 9

You plan to use VNET4 for an Azure API Management implementation.

You need to configure a policy that can be used by an Azure application gateway to protect against known web attack vectors. The policy must only allow requests that originate from IP addresses in Canada. You do NOT need to create the application gateway to complete this task.

Full Access
Question # 11

Your company has offices in London, Tokyo, and New York.

The company has a web app named App1 that has the Azure Traffic Manager profile shown in the following table.

In Asia, you plan to deploy an additional endpoint that will host an updated version of App1. You need to route 10 percent of the traffic from the Tokyo office to the new endpoint during testi What should you configure in Traffic Manager?

A.

one profile and five endpoints

B.

two profiles and four endpoints

C.

three profiles and four endpoints

D.

two profiles and five endpoints

Full Access
Question # 12

Task 8

You need to ensure that the storage34280945 storage account will only accept connections from hosts on VNET1

Full Access
Question # 13

Task 3

You plan to implement an Azure application gateway in the East US Azure region. The application gateway will have Web Application Firewall (WAF) enabled.

You need to create a policy that can be linked to the planned application gateway. The policy must block connections from IP addresses in the 131.107.150.0/24 range. You do NOT need to provision the application gateway to complete this task.

Full Access
Question # 14

You have an Azure virtual network named VNet1 that contains the subnets shown in the following table.

You need to deploy an Azure application gateway named AppGW1 to VNetl To where can you deploy AppGW1?

A.

GatewaySubnet only

B.

Subnet2 only

C.

Subnet1 or Subnet2 only

D.

Subnet2 or GatewaySubnet only

E.

Subnet1, Subnet2, and GatewaySubnet

Full Access
Question # 15

Task 7

You need to ensure that hosts on VNET2 can access hosts on both VNET1 and VNET3. The solution must prevent hosts on VNET1 and VNET3 from communicating through VNET2.

Full Access
Question # 16

You have an Azure subscription that contains six Azure App Service apps. The apps have an identical configuration and are deployed across multiple Azure regions.

You plan to deploy Azure Front Door to load balance traffic across the apps.

You need to ensure that the round robin load-balancing algorithm will send traffic only to a limited number App Service apps based on their proximity to a user. The solution must minimize administrative effort.

What should you modify, and what should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 17

Task 11

You need to ensure that only hosts on VNET1 can access the slcnage42150372 storage account. The solution must ensure that access occurs over the Azure backbone network.

Full Access
Question # 18

You have an Azure subscription that contains the resources shown in the following table.

You plan to deploy an Azure Virtual Network NAT gateway named Gateway 1. The solution must meet the following requirements:

• VM1 will access the internet by using its public IP address.

• VM2 will access the internet by using its public IP address.

• Administrative effort must be minimized.

You need to ensure that you can deploy Gateway1 to Vnet1.

What is the minimal number of subnets that Vnet1 must have?

A.

2

B.

3

C.

4

D.

5

Full Access
Question # 19

You need to implement outbound connectivity for VMScaleSet1. The solution must meet the virtual networking requirements and the business requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 20

You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements.

Which two actions should you include in the solution? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

On the peerings from Vnet2 and Vnet3, select Use remote gateways.

B.

On the peering from Vnet1, select Allow forwarded traffic.

C.

On the peering from Vnet1, select Use remote gateways.

D.

On the peering from Vnet1, select Allow gateway transit.

E.

On the peerings from Vnet2 and Vnet3, select Allow gateway transit.

Full Access
Question # 21

You need to restrict traffic from VMScaleSet1 to VMScaleSet2. The solution must meet the virtual networking requirements.

What is the minimum number of custom NSG rules and NSG assignments required? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 22

You have an Azure subscription that contains the virtual machines shown in the following table.

VNet1 and VNet2 are NOT connected to each other.

You need to block traffic from SQL Server 2019 to IIS by using application security groups. The solution must minimize administrative effort.

How should you configure the application security groups? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 23

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure subscription that contains the following resources:

* A virtual network named Vnet1

* A subnet named Subnet1 in Vnet1

* A virtual machine named VM1 that connects to Subnet1

* Three storage accounts named storage1, storage2, and storage3

You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other storage accounts.

Solution: You create a network security group (NSG) and associate the NSG to Subnet1.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 24

You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements.

What should you include in the solution?

A.

a service endpoint

B.

Azure Front Door

C.

a private endpoint

D.

Azure Traffic Manager

Full Access
Question # 25

STION NO: 2 DRAG DROP

You need to prepare Vnet1 for the deployment of an ExpressRoute gateway. The solution must meet the hybrid connectivity requirements and the business requirements.

Which three actions should you perform in sequence for Vnet1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 26

You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2.

You have the NAT gateway shown in the NATgateway1 exhibit.

You have the virtual machine shown in the VM1 exhibit.

Subnet1 is configured as shown in the Subnet1 exhibit.

For each of the following statements, select Yes of the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 27

You need to implement a P2S VPN for the users in the branch office. The solution must meet the hybrid networking requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 28

You need to provide access to storage2. The solution must meet the PaaS networking requirements and the business requirements.

Which connectivity method should you use?

A.

a service endpoint

B.

a private endpoint

C.

Azure Firewall

D.

Azure Front Door

Full Access
Question # 29

You have an Azure subscription that contains an instance of Azure Firewall Standard named AzFW1. You plan to enable the following:

• TLS inspection

• Threat intelligence

• A network intrusion detection and prevention system (IDPS)

What can you enable by using AzFW1?

A.

TLS inspection only

B.

threat intelligence only

C.

TLS inspection and the IDPS only

D.

threat intelligence and the IDPS only

E.

TLS inspection, threat intelligence, and the IDPS

Full Access
Question # 30

You have an Azure application gateway configured for a single website that is available at https://www.contoso.com.

The application gateway contains one backend pool and one rule. The backend pool contains two backend servers. Each backend server has an additional website that is available on port 8080.

You need to ensure that if port 8080 is unavailable on a backend server, all the traffic for https://www.contoso.com is redirected to the other ba ckend server.

What should you do?

A.

Create a health probe.

B.

Add a new rule.

C.

Add a new listener.

D.

Change the port on the listener.

Full Access
Question # 31

You have an Azure virtual network named Vnet1 that hosts an Azure firewall named FW1 and 150 virtual machines. Vnet1 is linked to a private DNS zone named contoso.com. All the virtual machines have their name registered in the contoso.com zone.

Vnet1 connects to an on-premises datacenter by using ExpressRoute.

You need to ensure that on-premises DNS servers can resolve the names in the contoso.com zone.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

On the on-premises DNS servers, configure forwarders that point to the frontend IP address of FW1.

B.

On the on-premises DNS servers, configure forwarders that point to the Azure provided DNS service at 168.63.129.16.

C.

Modify the DNS server settings of Vnet1.

D.

For FW1, enable DNS proxy.

E.

For FW1, configure a custom DNS server.

Full Access
Question # 32

You have an Azure subscription that contains a virtual network named Vnetl. Vnetl has a /24 IPv4 address space.

You need to subdivide Vnet1. The solution must maximize the number of usable subnets.

What is the maximum number of IPv4 subnets you can create, and how many usable IP addresses will be available per subnet? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 33

You have an Azure virtual network that contains two subnets named Subnet1 and Subnet2. Subnet1 contains a virtual machine named VM1. Subnet2 contains a virtual machine named VM2.

You have two network security groups (NSGs) named NSG1 and NSG2. NSG1 has 100 inbound security rules and is associated to VM1. NSG2 has 200 inbound security rules and is associated to Subnet1.

VM2 cannot connect to VM1.

You suspect that an NSG rule blocks connectivity.

You need to identify which rule blocks the connection. The issue must be resolved as quickly as possible.

Which Azure Network Watcher feature should you use?

A.

Effective security rules

B.

Connection troubleshoot

C.

NSG diagnostic

D.

NSG flow logs

Full Access
Question # 34

You have an Azure subscription. The subscription contains a locally-redundant storage 1LRS) account named stoiage1 that is deployed to the US East Azure region and has a Microsoft Storage service endpoint.

You set Redundancy for storage 1 to Read-access geo-redundant storage (RA-GRS)

You need to ensure that the contents of storage1 will be accessible by using a service endpoint in a paired region. The solution must minimize administrative effort

What should you do first?

A.

Create an object replication rule for storage1.

B.

From storage1. select Secure transfer required.

C.

Create a service endpoint policy.

D.

Delete the existing service endpoint.

Full Access
Question # 35

You have an Azure subscription that contains a virtual network name Vnet1. Vnet1 contains a virtual machine named VM1 and an Azure firewall named FW1.

You have an Azure Firewall Policy named FP1 that is associated to FW1.

You need to ensure that RDP requests to the public IP address of FW1 route to VM1.

What should you configure on FP1?

A.

an application rule

B.

a network rule

C.

URL filtering

D.

a DNAT rule

Full Access
Question # 36

You have the Azure firewall shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Full Access
Question # 37

NO: 6 HOTSPOT

You have an Azure application gateway named AppGW1 that provides access to the following hosts:

* www.adatum.com

* www.contoso.com

* www.fabrikam.com

AppGW1 has the listeners shown in the following table.

You create Azure Web Application Firewall (WAF) policies for AppGW1 as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 38

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.

You configure the application gateway to direct traffic to the URL of the application gateway.

You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.

Solution: You disable the WAF rule that has a ruleld of 920300.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 39

You have the on-premises networks shown in the following table.

You have an Azure subscription that contains an Azure virtual WAN named VWAN1 and a virtual network named VNet1 VWAN1 is connected to the on-premises networks and VNet1 in a full mesh topology. The virtual hub routing preference for VWAN1 is AS Path.

You need to route traffic from VNet1 to 10.61.1.5.

Which path will be used?

A.

the ExpressRoute connection to Branch2

B.

the ExpressRoute connection to Branch3

C.

the VPN connection to Branch1

D.

the VPN connection to Branch2

Full Access
Question # 40

N NO: 1

You need to configure the default route on Vnet2 and Vnet3. The solution must meet the virtual networking requirements.

What should you use to configure the default route?

A.

route filters

B.

BGP route exchange

C.

a user-defined route assigned to GatewaySubnet in Vnet1

D.

a user-defined route assigned to GatewaySubnet in Vnet2 and Vnet3

Full Access
Question # 41

You are implementing the virtual network requirements for VM Analyze.

What should you include in a custom route that is linked to Subnet2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 42

You create NSG10 and NSG11 to meet the network security requirements.

For each of the following statements, select Yes it the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 43

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 44

What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?

A.

a private endpoint

B.

a virtual network peering

C.

a private link service

D.

a routing table

E.

a service endpoint

Full Access
Question # 45

In which NSGs can you use ASG1 and to which virtual machine network interfaces can you associate ASG1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 46

You are implementing the Virtual network requirements for Vnet6.

What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 47

Which virtual machines can VM1 and VM4 ping successfully? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 48

You have an Azure subscription that contains the resources shown in the following table.

You need to configure a solution to meet the following requirements;

• App1 must be assigned a private endpoint

• Access to App1 from the internet must be routed via FD1.

What should you configure on FD1?

A.

a rule that has the route configuration override action

B.

a route that redirects traffic

C.

an origin that enables the Azure Private Link service

D.

a security policy that redirects traffic

Full Access
Question # 49

You have an Azure application gateway named AGW1 that has a routing rule named Rule1. Rule 1 directs traffic for http://www.contoso.com to a backend poo l named Pool1. Pool1 targets an Azure virtual machine scale set named VMSS1.

You deploy another virtual machine scale set named VMSS2.

You need to configure AGW1 to direct all traffic for http://www.adatum.com to VMSS2.

The solution must ensure that requests to http://www.contoso.com continue to be directed to Pool1.

Which three actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Add a backend pool.

B.

Modify an HTTP setting.

C.

Add an HTTP setting.

D.

Add a listener.

E.

Add a rule.

Full Access
Question # 50

You have an Azure subscription that contains an app named Appl. App1 is hosted on the Azure App Service instances shown in the following table.

You need to implement Azure Traffic Manager to meet the following requirements:

• App1 traffic must be assigned equally to each App Service instance in each Azure region.

• App1 traffic from North Europe must be routed to the Appl instances in the North Europe region.

• App1 traffic from North America must be routed to the Appl instances in the East US Azure region.

Full Access
Question # 51

You have two Azure virtual networks named VNet1 and VNet2 that are peered with each other. VNet1 hosts 10 virtual machines that contain web servers. VNet2 hosts five virtual machines that contain database servers.

You need to configure a security solution that meets the following requirements:

• Ensures that the database servers can accept connections only from the web servers

• Ensures that the web servers can initiate connections only to the database servers

• Ensures that all network security groups (NSGs) are associated only with subnets

• Use application security groups to implement the solution

What is the minimum number of application security groups required?

A.

1

B.

2

C.

4

D.

8

Full Access
Question # 52

You have the Azure subscriptions shown in the following table.

Each virtual network contains 20 internet-accessible resources that are assigned public IP addresses.

You need to implement Azure DDoS Network Protection to protect the resources. The solution must minimize costs.

What is the minimum number of DDoS Network Protection plans you should deploy?

A.

1

B.

2

C.

3

D.

6

Full Access