Winter Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

AZ-700 Designing and Implementing Microsoft Azure Networking Solutions Questions and Answers

Questions 4

You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements.

What should you include in the solution?

Options:

A.

a service endpoint

B.

Azure Front Door

C.

a private endpoint

D.

Azure Traffic Manager

Buy Now
Questions 5

You need to implement outbound connectivity for VMScaleSet1. The solution must meet the virtual networking requirements and the business requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-700 Question 5

Options:

Buy Now
Questions 6

You need to implement a P2S VPN for the users in the branch office. The solution must meet the hybrid networking requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 6

Options:

Buy Now
Questions 7

You need to restrict traffic from VMScaleSet1 to VMScaleSet2. The solution must meet the virtual networking requirements.

What is the minimum number of custom NSG rules and NSG assignments required? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 7

Options:

Buy Now
Questions 8

You need to provide access to storage2. The solution must meet the PaaS networking requirements and the business requirements.

Which connectivity method should you use?

Options:

A.

a service endpoint

B.

a private endpoint

C.

Azure Firewall

D.

Azure Front Door

Buy Now
Questions 9

STION NO: 2 DRAG DROP

You need to prepare Vnet1 for the deployment of an ExpressRoute gateway. The solution must meet the hybrid connectivity requirements and the business requirements.

Which three actions should you perform in sequence for Vnet1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-700 Question 9

Options:

Buy Now
Questions 10

You need to recommend a configuration for the ExpressRoute connection from the Boston datacenter. The solution must meet the hybrid networking requirements and business requirements.

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 10

Options:

Buy Now
Questions 11

You need to configure the default route in Vnet2 and Vnet3. The solution must meet the virtual networking requirements.

What should you use to configure the default route?

Options:

A.

a user-defined route assigned to GatewaySubnet in Vnet2 and Vnet3

B.

a user-defined route assigned to GatewaySubnet in Vnet1

C.

BGP route exchange

D.

route filters

Buy Now
Questions 12

N NO: 1

You need to configure the default route on Vnet2 and Vnet3. The solution must meet the virtual networking requirements.

What should you use to configure the default route?

Options:

A.

route filters

B.

BGP route exchange

C.

a user-defined route assigned to GatewaySubnet in Vnet1

D.

a user-defined route assigned to GatewaySubnet in Vnet2 and Vnet3

Buy Now
Questions 13

You create NSG10 and NSG11 to meet the network security requirements.

For each of the following statements, select Yes it the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 13

Options:

Buy Now
Questions 14

You need to meet the network security requirements for the NSG flow logs.

Which type of resource do you need, and how many instances should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 14

Options:

Buy Now
Questions 15

You have an Azure subscription that contains six Azure App Service apps. The apps have an identical configuration and are deployed across multiple Azure regions.

You plan to deploy Azure Front Door to load balance traffic across the apps.

You need to ensure that the round robin load-balancing algorithm will send traffic only to a limited number App Service apps based on their proximity to a user. The solution must minimize administrative effort.

What should you modify, and what should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 15

Options:

Buy Now
Questions 16

You are implementing the Virtual network requirements for Vnet6.

What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 16

Options:

Buy Now
Questions 17

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 17

Options:

Buy Now
Questions 18

What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?

Options:

A.

a private endpoint

B.

a virtual network peering

C.

a private link service

D.

a routing table

E.

a service endpoint

Buy Now
Questions 19

You need to configure GW1 to meet the network security requirements for the P2S VPN users.

Which Tunnel type should you select in the Point-to-site configuration settings of GW1?

Options:

A.

IKEv2 and OpenVPN (SSL)

B.

IKEv2

C.

IKEv2 and SSTP (SSL)

D.

OpenVPN (SSL)

E.

SSTP (SSL)

Buy Now
Questions 20

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 20

Options:

Buy Now
Questions 21

In which NSGs can you use ASG1 and to which virtual machine network interfaces can you associate ASG1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 21

Options:

Buy Now
Questions 22

You are implementing the virtual network requirements for VM Analyze.

What should you include in a custom route that is linked to Subnet2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 22

Options:

Buy Now
Questions 23

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.

Options:

Buy Now
Questions 24

Which virtual machines can VM1 and VM4 ping successfully? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 24

Options:

Buy Now
Questions 25

You have an Azure subscription that contains the resources shown in the following table.

AZ-700 Question 25

You plan to deploy an Azure Virtual Network NAT gateway named Gateway 1. The solution must meet the following requirements:

• VM1 will access the internet by using its public IP address.

• VM2 will access the internet by using its public IP address.

• Administrative effort must be minimized.

You need to ensure that you can deploy Gateway1 to Vnet1.

What is the minimal number of subnets that Vnet1 must have?

Options:

A.

2

B.

3

C.

4

D.

5

Buy Now
Questions 26

Task 6

You need to ensure that all hosts deployed to subnet3-2 connect to the internet by using the same static public IP address. The solution must minimize administrative effort when adding hosts to the subnet.

Options:

Buy Now
Questions 27

Task 6

You have two servers that are each hosted by a separate service provider in New York and Germany. The server hosted in New York is accessible by using a host name of ny.contoso.com. The server hosted in Germany is accessible by using a host name of de.contoso.com.

You need to provide a single host name to access both servers. The solution must ensure that traffic originating from Germany is routed to de contoso.com. All other traffic must be routed to ny.contoso.com.

Options:

Buy Now
Questions 28

Task 8

You plan to deploy an appliance to subnet3-2- The appliance will perform packet inspection and will have an IP address of 10.3.2.100.

You need to ensure that all traffic to the internet from subnet3-1 is forwarded to the appliance for inspection.

Options:

Buy Now
Questions 29

Task 9

You plan to use VNET4 for an Azure API Management implementation.

You need to configure a policy that can be used by an Azure application gateway to protect against known web attack vectors. The policy must only allow requests that originate from IP addresses in Canada. You do NOT need to create the application gateway to complete this task.

Options:

Buy Now
Questions 30

You have an Azure subscription that contains an ExpressRoute Standard gateway named GW1.

You need to upgrade GW1 to support ExpressRoute FastPath. The solution must minimize downtime.

Which SKU should you use?

Options:

A.

ErGw3AZ

B.

ErGw2AZ

C.

High performance

D.

Ultra performance

Buy Now
Questions 31

Your on-premises network uses an IP address range of 10.1.0.0 to 10.1.255.255.

You plan to deploy a new Azure virtual network solution that will include the following elements:

• A virtual network named VNet1

• A Site-to-Site (S2S) VPN connection between VNet1 and the on-premises network

• GatewaySubnet in VNet1, which will be used as a route-based virtual network gateway

You need to recommend which subnet masks to assign to VNet1 and GatewaySubnet. The solution must meet the following requirements:

• Maximize the number of available IP addresses on VNet1.

• Minimize the number of available IP addresses on GatewaySubnet

Which address spaces should you assign to VNet1 and GatewaySubnet? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 31

Options:

Buy Now
Questions 32

You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements.

Which two actions should you include in the solution? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

On the peerings from Vnet2 and Vnet3, select Use remote gateways.

B.

On the peering from Vnet1, select Allow forwarded traffic.

C.

On the peering from Vnet1, select Use remote gateways.

D.

On the peering from Vnet1, select Allow gateway transit.

E.

On the peerings from Vnet2 and Vnet3, select Allow gateway transit.

Buy Now
Questions 33

You have an Azure subscription that contains a resource group named RG1 and a virtual network named VNet1 You need to deploy Azure Firewall to RG1. The solution must minimize administrative effort What should you do first?

Options:

A.

Create a secured virtual hub named AzureFirewallHub.

B.

Create a new resource group named AzureFirewallResourceGroup.

C.

Create a new virtual network named AzureFirewallNetwork.

D.

On VNet1, create a virtual subnet named AzureFirewallSubnet.

Buy Now
Questions 34

Task 7

You need to ensure that hosts on VNET2 can access hosts on both VNET1 and VNET3. The solution must prevent hosts on VNET1 and VNET3 from communicating through VNET2.

Options:

Buy Now
Questions 35

Your company has 40 branch offices that are linked by using a Software-Defined Wide Area Network (SD-WAN). The SD-WAN uses

BGP.

You have an Azure subscription that contains 20 virtual networks configured as a hub and spoke topology. The topology contains a hub virtual network named Vnetl.

The virtual networks connect to the SD-WAN by using a network virtual appliance (NVA) in Vnetl.

You need to ensure that BGP route advertisements will propagate between the virtual networks and the SD-WAN. The solution must minimize administrative effort

What should you implement?

Options:

A.

An Azure VPN Gateway that has BGP enabled

B.

a NAT gateway

C.

Azure Traffic Manager

D.

Azure Route Server

Buy Now
Questions 36

Task 11

You are preparing to connect your on-premises network to VNET4 by using a Site-to-Site VPN. The on-premises endpoint of the VPN will be created on a firewall named Firewall 1.

The on-premises network has the following configurations:

• Internal address range: 10.10.0.0/16.

• Firewall 1 internal IP address: 10.10.1.1.

• Firewall1 public IP address: 131.107.50.60.

BGP is NOT used.

You need to create the object that will provide the IP addressing configuration of the on-premises network to the Site-to-Site VPN. You do NOT need to create a virtual network gateway to complete this task.

Options:

Buy Now
Questions 37

Task 2

You need to ensure that you can deploy Azure virtual machines to the France Central Azure region. The solution must ensure that virtual machines in the France Central region are in a network segment that has an IP address range of 10.5.1.0/24.

Options:

Buy Now
Questions 38

Task 7

You plan to deploy 100 virtual machines to subnet4-1. The virtual machines will NOT be assigned a public IP address. The virtual machines will call the same API. which is hosted by a third party. The virtual machines will make more than 10,000 calls per minute to the API.

You need to minimize the risk of SNAT port exhaustion. The solution must minimize administrative effort.

Options:

Buy Now
Questions 39

You have an Azure subscription that contains a virtual network.

You plan to deploy an Azure VPN gateway and 90 Site-to-Site VPN connections. The solution must meet the following requirements:

• Ensure that the Site-to-Site VPN connections remain available if an Azure datacenter fails.

• Minimize costs.

Which gateway SKU should you specify?

Options:

A.

VpnGwIAZ

B.

VpnGw2AZ

C.

VpnGw4AZ

D.

VpnGwSAZ

Buy Now
Questions 40

Task 9

You need to ensure that subnet4-3 can accommodate 507 hosts.

Options:

Buy Now
Questions 41

Task 10

You need to configure VNET1 to log all events and metrics. The solution must ensure that you can query the events and metrics directly from the Azure portal by using KQL.

Options:

Buy Now
Questions 42

Task 1

You need to ensure that virtual machines on VNET1 and VNET2 are included automatically in a DNS zone named contoso.azure. The solution must ensure that the virtual machines on VNET1 and VNET2 can resolve the names of the virtual machines on either virtual network.

Options:

Buy Now
Questions 43

You have an Azure subscription that contains the resources shown in the following table.

AZ-700 Question 43

You discover that users connect directly to App1.

You need to meet The following requirements:

• Administrators must only access App1 by using a private endpoint.

• All user connections to App1 must be routed through FD1.

• The downtime of connections to App1 must be minimized.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.

AZ-700 Question 43

Options:

Buy Now
Questions 44

You have two Azure virtual networks named VNet1 and VNet2 that are peered with each other. VNet1 hosts 10 virtual machines that contain web servers. VNet2 hosts five virtual machines that contain database servers.

You need to configure a security solution that meets the following requirements:

• Ensures that the database servers can accept connections only from the web servers

• Ensures that the web servers can initiate connections only to the database servers

• Ensures that all network security groups (NSGs) are associated only with subnets

• Use application security groups to implement the solution

What is the minimum number of application security groups required?

Options:

A.

1

B.

2

C.

4

D.

8

Buy Now
Questions 45

You have an Azure subscription that contains a virtual network named VNet1. VNet1 uses an IP address space of 192.168.0.0/24. You plan to deploy Azure virtual machines and Azure Bastion to VNet1.

You need to recommend an IP subnetting configuration for VNet1. The solution must maximize the number of IP addresses that can be assigned to the virtual machines

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 45

Options:

Buy Now
Questions 46

Azure virtual networks in the East US Azure region as shown in the following table.

AZ-700 Question 46

The virtual networks are peered to one another. Each virtual network contains four subnets.

You plan to deploy a virtual machine named VM1 that will inspect and route traffic between all the subnets on both the virtual networks.

What is the minimum number of IP addresses that you must assign to VM1?

Options:

A.

1

B.

2

C.

4

D.

8

Buy Now
Questions 47

You have an Azure virtual network that contains a subnet named Subnet1. Subnet1 is associated to a network security group (NSG) named NSG1. NSG1 blocks all outbound traffic that is not allowed explicitly.

Subnet1 contains virtual machines that must communicate with the Azure Cosmos DB service.

You need to create an outbound security rule in NSG1 to enable the virtual machines to connect to Azure Cosmos DB.

What should you include in the solution?

Options:

A.

a service tag

B.

a private endpoint

C.

a subnet delegation

D.

an application security group

Buy Now
Questions 48

You have an Azure subscription that contains 1.000 virtual machines.

You collect network security group (NSG) flow logs.

You need to identify all the virtual machines that have interacted with non-Azure public IP addresses during the last 30 days

How should you complete the query? To answer, select the appropriate options in the answer area

NOTE; Each correct selection is worth one point.

AZ-700 Question 48

Options:

Buy Now
Questions 49

You have two Azure virtual networks named Hub1 and Spoke1. Hub1 connects to an on-premises network by using a Site-to-Site VPN connection.

You are implementing peering between Hub1 and Spoke1.

You need to ensure that a virtual machine connected to Spoke1 can connect to the on-premises network through Hub1.

How should you complete the PowerShell script? To answer, drag the appropriate values to the correct targets. Each value may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

AZ-700 Question 49

Options:

Buy Now
Questions 50

You have the on-premises networks shown in the following table.

AZ-700 Question 50

You have an Azure subscription that contains an Azure virtual WAN named VWAN1 and a virtual network named VNet1 VWAN1 is connected to the on-premises networks and VNet1 in a full mesh topology. The virtual hub routing preference for VWAN1 is AS Path.

You need to route traffic from VNet1 to 10.61.1.5.

Which path will be used?

Options:

A.

the ExpressRoute connection to Branch2

B.

the ExpressRoute connection to Branch3

C.

the VPN connection to Branch1

D.

the VPN connection to Branch2

Buy Now
Questions 51

Your company has four branch offices and an Azure Subscription. The subscription contains an Azure VPN gateway named GW1.

The branch offices are configured as shown in the following table.

AZ-700 Question 51

The branch office routers provide internet connectivity and Site-to-Site VPN connections to GW1.

The users in Branch1 report that they can connect to internet resources, but cannot access Azure resources.

You need to ensure that the Branch1 users can connect to the Azure Resources. The solution must meet the following requirements:

• Minimize downtime for all users.

• Minimize administrative effort.

What should you do first?

Options:

A.

Reset RTR1.

B.

Reset Connection1.

C.

Reset GW1.

D.

Recreate LNG1.

Buy Now
Questions 52

You have an Azure subscription that contains the public IP addresses shown in the following table.

AZ-700 Question 52

You plan to deploy a NAT gateway named NAT1.

Which public IP addresses can be used as the public IP address for NAT1?

Options:

A.

IP3 and IP5 only

B.

IP5 only

C.

IP1, IP3, and IP5 only

D.

IP3 only

E.

IP2 and IP4 only

Buy Now
Questions 53

You have the resources shown in the following table.

AZ-700 Question 53

From the Microsoft Entra admin center, you register the Azure VPN application as an enterprise application.

You need to enable Microsoft Entra authentication for the P2S VPN connections. The solution must meet the following requirements;

• Ensure that only the members of Group1 can establish VPN connections to VPNGW1.

• Ensure that only the members of Group2 can establish VPN connections to VPNGW2.

In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

AZ-700 Question 53

Options:

Buy Now
Questions 54

You have an Azure Virtual Desktop deployment that has 500 session hosts.

All outbound traffic to the internet uses a NAT gateway.

During peak business hours, some users report that they cannot access internet resources. In Azure Monitor, you discover many failed SNAT connections.

You need to increase the available SNAT connections.

What should you do?

Options:

A.

Add a public IP address.

B.

Bind the NAT gateway to another subnet.

C.

Deploy Azure Standard Load Balancer that has outbound rules.

Buy Now
Questions 55

You are configuring two network virtual appliances (NVAs) in an Azure virtual network. The NVAs will be used to inspect all the traffic within the virtual network.

You need to provide high availability for the NVAs. The solution must minimize administrative effort. What shtraffic ould you include in the solution?

Options:

A.

Azure Standard Load Balancer

B.

Azure Traffic Manager

C.

Azure Application Gateway

D.

Azure Front Door

Buy Now
Questions 56

You have the Azure virtual networks shown in the following table.

AZ-700 Question 56

You have the Azure resources shown in the following table.

AZ-700 Question 56

You need to check latency between the resources by using connection monitors in Azure Network Watcher.

What is the minimum number of connection monitors that you must create?

Options:

A.

1

B.

2

C.

3

D.

4

E.

5

Buy Now
Questions 57

You have an Azure subscription.

You plan to deploy Azure Firewall Premium, enable all the Premium features, and configure both network and application rules.

Which type of rule will the firewall process first?

Options:

A.

infrastructure

B.

network

C.

threat intelligence

D.

application

Buy Now
Questions 58

You have an Azure application gateway for a web app named App1. The application gateway allows end-to-end encryption.

You configure the listener for HTTPS by uploading an enterprise signed certificate.

You need to ensure that the application gateway can provide end-to-end encryption for App1. What should you do?

Options:

A.

Set Listener type to Multi site.

B.

Increase the Unhealthy threshold setting in the custom probe.

C.

Upload the public key certificate to the HTTPS settings.

D.

Enable the SSL profile for the listener.

Buy Now
Questions 59

You have the Azure Traffic Manager profiles shown in the following table.

AZ-700 Question 59

You plan to add the endpoints shown in the following table.

AZ-700 Question 59

Which endpoints can you add to Profile2?

Options:

A.

Endpoint1 and Endpoint4 only

B.

Endpoint1, Endpoint2, Endpoint3, and Endpoint4

C.

Endpoint1 only

D.

Endpoint2 and Endpoint3 only

E.

Endpoint3 only

Buy Now
Questions 60

You have the Azure environment shown In the Azure Environment exhibit. (Click the Azure Environment tab.) The settings for each subnet are shown in the following table.

AZ-700 Question 60

The Firewalls and virtual networks settings for storage1 are configured as shown in the Storage1 exhibit. (Click the Storage1 tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

AZ-700 Question 60

Options:

Buy Now
Questions 61

You have an Azure subscription.

You plan 10 implement an Azure application gateway named AGW1.

You need to implement an external TLS certificate store for AGW1. The solution must meet the following requirements:

• Keys must be stored by using the highest possible security.

• Administrative effort must be minimized.

Which type of certificate store should you use, and which type of identity should you use to access the store? To answer, select the appropriate options in the answer area.

NOTE: Each correct answer is worth one point.

AZ-700 Question 61

Options:

Buy Now
Questions 62

You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2.

You have the NAT gateway shown in the NATgateway1 exhibit.

AZ-700 Question 62

You have the virtual machine shown in the VM1 exhibit.

AZ-700 Question 62

Subnet1 is configured as shown in the Subnet1 exhibit.

AZ-700 Question 62

For each of the following statements, select Yes of the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 62

Options:

Buy Now
Questions 63

You have an Azure subscription that contains a virtual network named Vnet1. Vnet1 contains 20 subnets and 500 virtual machines. Each subnet contains a virtual machine that runs network monitoring software.

You have a network security group (NSG) named NSG1 associated to each subnet.

When a new subnet is created in Vnet1, an automated process creates an additional network monitoring virtual machine in the subnet and links the subnet to NSG1.

You need to create an inbound security rule in NS61 that will allow connections to the network monitoring virtual machines from an IP address of 131.107.1.15. The solution must meet the following requirements:

• Ensure that only the monitoring virtual machines receive a connection from 131.107.1.15.

• Minimize changes to NSG1 when a new subnet is created.

What should you use as the destination in the inbound security rule?

Options:

A.

a virtual network

B.

an IP address

C.

an application security group

D.

a service tag

Buy Now
Exam Code: AZ-700
Exam Name: Designing and Implementing Microsoft Azure Networking Solutions
Last Update: Jan 15, 2025
Questions: 276

PDF + Testing Engine

$70  $174.99

Testing Engine

$54  $134.99
buy now AZ-700 testing engine

PDF (Q&A)

$46  $114.99
buy now AZ-700 pdf