[Jan 17, 2022] Dumps Collection AZ-700 Test Engine Dumps Training With 98 Questions [Q57-Q76]

Share

[Jan 17, 2022] Dumps Collection AZ-700 Test Engine Dumps Training With 98 Questions

Microsoft AZ-700 Dumps - 100% Cover Real Exam Questions


Skills measured

  • Design, Implement, and Manage Hybrid Networking (10% to 15%)
  • Design and Implement Core Networking Infrastructure (20% to 25%)
  • Design and Implement Private Access to Azure Services (10% to 15%)
  • Design and Implement Routing (25% to 30%)
  • Secure and Monitor Networks (15% to 20%)

Microsoft AZ-700 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Design, implement, and manage a site-to-site VPN connection
  • Diagnose and resolve VPN gateway connectivity issues
Topic 2
  • Identify when to use policy-based VPN versus route-based VPN
  • Plan and configure certificate-based authentication
Topic 3
  • Create and configure an Azure Load Balancer (including cross-region)
  • Recommend Azure Application Gateway deployment options
Topic 4
  • Plan and configure Azure Active Directory (Azure AD) authentication
  • Design a site-to-site VPN connection for high availability
Topic 5
  • Create and configure a virtual network gateway
  • Design, Implement, and Manage Hybrid Networking
Topic 6
  • Configure VNet integration for dedicated platform as a service (PaaS) services
  • Design and implement Azure Private Link service and Azure Private Endpoint
Topic 7
  • Diagnose and resolve client-side and authentication issues
  • Design and implement Azure cross-region connectivity between multiple ExpressRoute

 

NEW QUESTION 57
You configure a route table named RT1 that has the routes shown in the following table.

You have an Azure virtual network named Vnet1 that has the subnets shown in the following table.

You have the resources shown in the following table.

Vnet1 connects to an ExpressRoute circuit. The on-premises router advertises the following routes:
* 0.0.0.0/0
* 10.0.0.0/16
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 58
You have an Azure Web Application Firewall (WAF) policy in prevention mode that is associated to an Azure Front Door instance.
You need to configure the policy to meet the following requirements:
* Log all connections from Australia.
* Deny all connections from New Zealand.
* Deny all further connections from a network of 131.107.100.0/24 if there are more than 100 connections during one minute.
What is the minimum number of objects you should create?

  • A. one custom rule that has three conditions
  • B. three custom rules that each has one condition
  • C. one custom rule that has one condition
  • D. one rule that has two conditions and another rule that has one condition

Answer: B

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/afds-overview

 

NEW QUESTION 59
You have an Azure firewall shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application, email Description automatically generated

Box 1:
If forced tunneling was enabled, the Firewall Subnet would be named AzureFirewallManagementSubnet.
Forced tunneling can only be enabled during the creation of the firewall. It cannot be enabled after the firewall has been deployed.
Box 2:
The "Visit Azure Firewall Manager to configure and manage this firewall" link in the exhibit shows that the firewall is managed by Azure Firewall Manager.

 

NEW QUESTION 60
You have five virtual machines that run Windows Server. Each virtual machine hosts a different web app.
You plan to use an Azure application gateway to provide access to each web app by using a hostname of www.contoso.corn and a different URL path for each web app, for example: https://www.contoso.com/app1.
You need to control the flow of traffic based on the URL path.
What should you configure?

  • A. listeners
  • B. rules
  • C. HTTP settings
  • D. rewrites

Answer: B

 

NEW QUESTION 61
You have an Azure application gateway for a web app named App1. The application gateway allows end-to-end encryption.
You configure the listener for HTTPS by uploading an enterprise signed certificate.
You need to ensure that the application gateway can provide end-to-end encryption for App1. What should you do?

  • A. Increase the Unhealthy threshold setting in the custom probe.
  • B. Upload the public key certificate to the HTTP settings.
  • C. Set Listener type to Multi site.
  • D. Enable the SSL profile for the listener.

Answer: D

 

NEW QUESTION 62
You plan to deploy an Azure virtual network.
You need to design the subnets.
Which three types of resources require a dedicated subnet? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Azure Active Directory Domain Services (Azure AD DS)
  • B. VPN gateway
  • C. Azure Private Link
  • D. Azure Application Gateway v2
  • E. Azure Bastion

Answer: A,C,D

 

NEW QUESTION 63
You have an application named App1 that listens for incoming requests on a preconfigured group of 50 TCP ports and UDP ports.
You install App1 on 10 Azure virtual machines.
You need to implement load balancing for App1 across all the virtual machines. The solution must minimize the number of load balancing rules.
What should you include in the solution?

  • A. Azure Standard Load Balancer that has high availability (HA) ports enabled
  • B. Azure Application Gateway V2 that has multiple listeners
  • C. Azure Application Gateway v2 that has multiple site hosting enabled
  • D. Azure Standard Load Balancer that has Floating IP enabled

Answer: D

 

NEW QUESTION 64
You create NSG10 and NSG11 to meet the network security requirements.
For each of the following statements, select Yes it the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 65
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
* A virtual network named Vnet1
* A subnet named Subnet1 in Vnet1
* A virtual machine named VM1 that connects to Subnet1
* Three storage accounts named storage1, storage2, and storage3
You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other storage accounts.
Solution: You configure the firewall on storage1 to only accept connections from Vnet1.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

 

NEW QUESTION 66
You are planning an Azure Point-to-Site (P2S) VPN that will use OpenVPN.
Users will authenticate by using an on premises Active Directory domain.
Which additional service should you deploy to support the VPN authentication?

  • A. a certification authority (CA)
  • B. Azure Active Directory (Azure AD) Application Proxy
  • C. an Azure key vault
  • D. a RADIUS server

Answer: D

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/point-to-site-about

 

NEW QUESTION 67
You have an Azure application gateway named AppGW1 that provides access to the following hosts:
* www.adatum.com
* www.contoso.com
* www.fabrikam.com
AppGW1 has the listeners shown in the following table.

You create Azure Web Application Firewall (WAF) policies for AppGW1 as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface Description automatically generated with medium confidence

Reference:
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/per-site-policies

 

NEW QUESTION 68
You have the Azure resources shown in the following table.

You configure storage1 to provide access to the subnet in Vnet1 by using a service endpoint.
You need to ensure that you can use the service endpoint to connect to the read-only endpoint of storage1 in the paired Azure region.
What should you do first?

  • A. Configure the firewall settings for storage1.
  • B. Create another service endpoint.
  • C. Fail over storage1 to the paired Azure region.
  • D. Create a virtual network in the paired Azure region.

Answer: A

 

NEW QUESTION 69
You have an Azure virtual network named Vnet1 that has one subnet. Vnet1 is in the West Europe Azure region.
You deploy an Azure App Service app named App1 to the West Europe region.
You need to provide App1 with access to the resources in Vnet1. The solution must minimize costs.
What should you do first?

  • A. Create a new subnet.
  • B. Create a NAT gateway.
  • C. Create a gateway subnet and deploy a virtual network gateway.
  • D. Create a private link.

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/app-service/web-sites-integrate-with-vnet

 

NEW QUESTION 70
You have an Azure subscription that contains the virtual machines shown in the following table.

Subnet1 and Subnet2 are associated to a network security group (NSG) named NSG1 that has the following outbound rule:
* Priority: 100
* Port: Any
* Protocol: Any
* Source: Any
* Destination: Storage
* Action: Deny
You create a private endpoint that has the following settings:
* Name: Private1
* Resource type: Microsoft.Storage/storageAccounts
* Resource: storage1
* Target sub-resource: blob
* Virtual network: Vnet1
* Subnet: Subnet1
For each of the following statements, select Yes of the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/private-link/disable-private-endpoint-network-policy

 

NEW QUESTION 71
You are planning an Azure solution that will contain the following types of resources in a single Azure region:
* Virtual machine
* Azure App Service
* Virtual Network gateway
* Azure SQL Managed Instance
App Service and SQL Managed Instance will be delegated to create resources in virtual networks.
You need to identify how many virtual networks and subnets are required for the solution. The solution must minimize costs to transfer data between virtual networks.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Diagram, table Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-for-azure-services#services-that-can-be-d

 

NEW QUESTION 72
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.
You configure the application gateway to direct traffic to the URL of the application gateway.
You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.
Solution: You create a WAF policy exclusion for request headers that contain 137.135.10.24.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

 

NEW QUESTION 73
In which NSGs can you use ASG1 and to which virtual machine network interfaces can you associate ASG1?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 74
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
* A virtual network named Vnet1
* A subnet named Subnet1 in Vnet1
* A virtual machine named VM1 that connects to Subnet1
* Three storage accounts named storage1, storage2. and storage3
You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other storage accounts.
Solution: You create a network security group (NSG). You configure a service tag for MicrosoftStorage and link the tag to Subnet1.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

 

NEW QUESTION 75
You have an Azure subscription that contains the public IPv4 addresses shown in the following table.

You plan to create a load balancer named LB1 that will have the following settings:
* Name: LB1
* Location: West US
* Type: Public
* SKU: Standard
Which public IPv4 addresses can be used by LB1?

  • A. IP3 and IP5 only
  • B. IP1, IP2. IP3. IP4. and IP5
  • C. IP1 and IP3 only
  • D. IP3 only
  • E. IP1, IP3, IP4, and 1P5 only
  • F. IP2only

Answer: B

 

NEW QUESTION 76
......

Realistic PassSureExam AZ-700 Dumps PDF - 100% Passing Guarantee: https://www.passsureexam.com/AZ-700-pass4sure-exam-dumps.html

Real AZ-700 dumps - Real Microsoft dumps PDF: https://drive.google.com/open?id=1vhBhgE7pxUfK_8Yn_-FzeOxwfe-GhhR-