AZ-700 Free Certification Exam Material from Prep4SureReview with 98 Questions Use Real AZ-700 - 100% Cover Real Exam Questions Schedule exam Languages: English Retirement date: none This exam measures your ability to design, implement, manage, secure, and monitor the following technical tasks: Hybrid Networking; Core Networking Infrastructure; Routing; Networks; and Private Access to Azure Services. [...]

AZ-700 Free Certification Exam Material from Prep4SureReview with 98 Questions [Q38-Q63]

Share

AZ-700 Free Certification Exam Material from Prep4SureReview with 98 Questions

Use Real AZ-700 - 100% Cover Real Exam Questions 


Schedule exam

Languages: English

Retirement date: none

This exam measures your ability to design, implement, manage, secure, and monitor the following technical tasks: Hybrid Networking; Core Networking Infrastructure; Routing; Networks; and Private Access to Azure Services.


Microsoft AZ-700 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Design and implement private IP addressing for VNets
  • Create explicit outbound rules for a load balancer
Topic 2
  • Create and configure an Azure Load Balancer (including cross-region)
  • Recommend Azure Application Gateway deployment options
Topic 3
  • Diagnose and resolve client-side and authentication issues
  • Design and implement Azure cross-region connectivity between multiple ExpressRoute
Topic 4
  • Create and configure a virtual network gateway
  • Design, Implement, and Manage Hybrid Networking
Topic 5
  • Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub
  • Design and implement an Azure Load Balancer
Topic 6
  • Configure VNet integration for dedicated platform as a service (PaaS) services
  • Design and implement Azure Private Link service and Azure Private Endpoint
Topic 7
  • Select an appropriate ExpressRoute SKU and tier
  • Select an appropriate virtual network (VNet) gateway SKU
Topic 8
  • Identify when to use policy-based VPN versus route-based VPN
  • Plan and configure certificate-based authentication
Topic 9
  • Design an Azure Virtual WAN architecture, including selecting SKUs and services
  • Connect a virtual network to an ExpressRoute circuit
Topic 10
  • Choose between private peering only, Microsoft peering only, or both
  • Choose between provider and direct model (ExpressRoute Direct)
Topic 11
  • Plan and configure Azure Active Directory (Azure AD) authentication
  • Design a site-to-site VPN connection for high availability
Topic 12
  • Design, implement, and manage a site-to-site VPN connection
  • Diagnose and resolve VPN gateway connectivity issues

 

NEW QUESTION 38
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have two Azure virtual networks named Vnet1 and Vnet2.
You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.
You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit. Vnet2 can use the remote gateway.
You discover that Client1 cannot communicate with Vnet2.
You need to ensure that Client1 can communicate with Vnet2.
Solution: You download and reinstall the VPN client configuration.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

Explanation:
Explanation
The VPN client must be downloaded again if any changes are made to VNet peering or the network topology.
Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-point-to-site-routing

 

NEW QUESTION 39
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.
You configure the application gateway to direct traffic to the URL of the application gateway.
You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.
Solution: You disable the WAF rule that has a ruleld of 920300.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

 

NEW QUESTION 40
You are configuring two network virtual appliances (NVAs) in an Azure virtual network. The NVAs will be used to inspect all the traffic within the virtual network.
You need to provide high availability for the NVAs. The solution must minimize administrative effort. What should you include in the solution?

  • A. Azure Standard Load Balancer
  • B. Azure Front Door
  • C. Azure Application Gateway
  • D. Azure Traffic Manager

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/nva-ha?tabs=cli

 

NEW QUESTION 41
You need to implement outbound connectivity for VMScaleSet1. The solution must meet the virtual networking requirements and the business requirements.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/load-balancer/skus
https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-outbound-connections#outboundrules

 

NEW QUESTION 42
You are implementing the Virtual network requirements for Vnet6.
What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:
2, 4

 

NEW QUESTION 43
What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?

  • A. a private link service
  • B. a virtual network peering
  • C. a service endpoint
  • D. a routing table
  • E. a private endpoint

Answer: B

Explanation:
Explanation
There is no virtual network peering between VM4's VNet (VNet3) and VM5's VNet (VNet4). To enable the VMs to communicate over the Microsoft backbone network a VNet peering is required between VNet3 and VNet4.

 

NEW QUESTION 44
You have an Azure Virtual Desktop deployment that has 500 session hosts.
All outbound traffic to the internet uses a NAT gateway.
During peak business hours, some users report that they cannot access internet resources. In Azure Monitor, you discover many failed SNAT connections.
You need to increase the available SNAT connections.
What should you do?

  • A. Deploy Azure Standard Load Balancer that has outbound rules.
  • B. Bind the NAT gateway to another subnet.
  • C. Add a public IP address.

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-gateway-resource

 

NEW QUESTION 45
You have the Azure environment shown in the exhibit.

VM1 is a virtual machine that has an instance-level public IP address (ILPIP).
Basic Load Balancer uses a public IP address. VM1 and VM2 are in the backend pool.
NAT Gateway uses a public IP address named IP3 that is associated to SubnetA.
VNet1 has a virtual network gateway that has a public IP address named IP4.
When initiating outbound traffic to the internet from VM1, which public address is used?

  • A. IP4
  • B. IP3
  • C. IP1
  • D. IP2

Answer: C

 

NEW QUESTION 46
You have an Azure Front Door instance that has a single frontend named Frontend1 and an Azure Web Application Firewall (WAF) policy named Policy1. Policy1 redirects requests that have a header containing
"string1" to https://www.contoso.com/redirect1. Policy1 is associated to Frontend1.
You need to configure additional redirection settings. Requests to Frontend1 that have a header containing
"string2" must be redirected to https://www.contoso.com/redirect2.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Create a policy.
  • B. Add a custom rule to Policy1.
  • C. Create an association.
  • D. Create a frontend host.
  • E. Configure a managed rule.
  • F. Create a custom rule.

Answer: C,E,F

 

NEW QUESTION 47
You have an Azure subscription.
You have the on-premises sites shown the following table.

You plan to deploy Azure Virtual WAN.
You are evaluating Virtual WAN Basic and Virtual WAN Standard.
Which type of Virtual WAN can you use for each site? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 48
You have an Azure Front Door instance named FrontDoor1.
You deploy two instances of an Azure web app to different Azure regions.
You plan to provide access to the web app through FrontDoor1 by using the name app1.contoso.com.
You need to ensure that FrontDoor1 is the entry point for requests that use app1.contoso.com.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

 

NEW QUESTION 49
You plan to deploy an Azure virtual network.
You need to design the subnets.
Which three types of resources require a dedicated subnet? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. VPN gateway
  • B. Azure Bastion
  • C. Azure Private Link
  • D. Azure Active Directory Domain Services (Azure AD DS)
  • E. Azure Application Gateway v2

Answer: A,B,E

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-for-azure-services

 

NEW QUESTION 50
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
* A virtual network named Vnet1
* A subnet named Subnet1 in Vnet1
* A virtual machine named VM1 that connects to Subnet1
* Three storage accounts named storage1, storage2. and storage3
You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other storage accounts.
Solution: You create a network security group (NSG). You configure a service tag for MicrosoftStorage and link the tag to Subnet1.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

 

NEW QUESTION 51
You have an Azure subscription that contains a single virtual network and a virtual network gateway.
You need to ensure that administrators can use Point-to-Site (P2S) VPN connections to access resources in the virtual network. The connections must be authenticated by Azure Active Directory (Azure AD).
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 52
You have the Azure resources shown in the following table.

You configure storage1 to provide access to the subnet in Vnet1 by using a service endpoint.
You need to ensure that you can use the service endpoint to connect to the read-only endpoint of storage1 in the paired Azure region.
What should you do first?

  • A. Configure the firewall settings for storage1.
  • B. Create another service endpoint.
  • C. Fail over storage1 to the paired Azure region.
  • D. Create a virtual network in the paired Azure region.

Answer: A

 

NEW QUESTION 53
You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements.
What should you include in the solution?

  • A. Azure Front Door
  • B. Azure Traffic Manager
  • C. a service endpoint
  • D. a private endpoint

Answer: B

 

NEW QUESTION 54
You have an Azure subscription that contains the public IP addresses shown in the following table.

You plan to deploy a NAT gateway named NAT1.
Which public IP addresses can be used as the public IP address for NAT1?

  • A. IP3 and IP5 only
  • B. IP1, IP3, and IP5 only
  • C. IP5 only
  • D. IP3 only
  • E. IP2 and IP4 only

Answer: D

Explanation:
Explanation
Only static IPv4 addresses in the Standard SKU are supported. IPv6 doesn't support NAT.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-overview

 

NEW QUESTION 55
You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2.
You have the NAT gateway shown in the NATgateway1 exhibit.

You have the virtual machine shown in the VM1 exhibit.

Subnet1 is configured as shown in the Subnet1 exhibit.

For each of the following statements, select Yes of the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

Box 1: No
VM1 is in Zone2 whereas the NAT Gateway is in Zone1. The VM would need to be in the same zone as the NAT Gateway to be able to use it. Therefore, VM1 cannot use the NAT gateway.
Box 2: Yes
NATgateway1 is configured in the settings for Subnet2.
Box 3: No
The NAT gateway does not have a single public IP address, it has an IP prefix which means more than one IP address. The VMs the use the NAT Gateway can use different public IP addresses contained within the IP prefix.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-gateway-resource

 

NEW QUESTION 56
You have an Azure subscription that contains the virtual machines shown in the following table.

Subnet1 and Subnet2 are associated to a network security group (NSG) named NSG1 that has the following outbound rule:
* Priority: 100
* Port: Any
* Protocol: Any
* Source: Any
* Destination: Storage
* Action: Deny
You create a private endpoint that has the following settings:
* Name: Private1
* Resource type: Microsoft.Storage/storageAccounts
* Resource: storage1
* Target sub-resource: blob
* Virtual network: Vnet1
* Subnet: Subnet1
For each of the following statements, select Yes of the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/private-link/disable-private-endpoint-network-policy

 

NEW QUESTION 57
You have the Azure App Service app shown in the App Service exhibit.

The VNet Integration settings for as12 are configured as shown in the Vnet Integration exhibit.

The Private Endpoint connections settings for as12 are configured as shown in the Private Endpoint connections exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/app-service/web-sites-integrate-with-vnet

 

NEW QUESTION 58
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.
You configure the application gateway to direct traffic to the URL of the application gateway.
You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.
Solution: You configure a custom cookie and an exclusion rule.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

 

NEW QUESTION 59
You have an application named App1 that listens for incoming requests on a preconfigured group of 50 TCP ports and UDP ports.
You install App1 on 10 Azure virtual machines.
You need to implement load balancing for App1 across all the virtual machines. The solution must minimize the number of load balancing rules.
What should you include in the solution?

  • A. Azure Standard Load Balancer that has high availability (HA) ports enabled
  • B. Azure Application Gateway V2 that has multiple listeners
  • C. Azure Application Gateway v2 that has multiple site hosting enabled
  • D. Azure Standard Load Balancer that has Floating IP enabled

Answer: D

 

NEW QUESTION 60
You have two Azure subscriptions named Subscnption1 and Subscription2. Subscription1 contains a virtual network named Vnet1. Vnet1 contains an application server. Subscription2 contains a virtual network named Vnet2.
You need to provide the virtual machines in Vnet2 with access to the application server in Vnet1 by using a private endpoint.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

 

NEW QUESTION 61
You fail to establish a Site-to-Site VPN connection between your company's main office and an Azure virtual network.
You need to troubleshoot what prevents you from establishing the IPsec tunnel.
Which diagnostic log should you review?

  • A. IKEDiagnosticLog
  • B. RouteDiagnosticLog
  • C. GatewayDiagnosticLog
  • D. TunnelDiagnosticLog

Answer: C

 

NEW QUESTION 62
You create NSG10 and NSG11 to meet the network security requirements.
For each of the following statements, select Yes it the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 63
......

Dumps Brief Outline Of The AZ-700 Exam: https://www.prep4surereview.com/AZ-700-latest-braindumps.html

AZ-700 Training & Certification Get Latest Microsoft Certified: Azure Network Engineer Associate : https://drive.google.com/open?id=1DvnkKvq8kG1_GLe_xdPMZnVep7H9ekL-