What Real AZ-700 Preparation Is

Want to know Examcollection AZ-700 Exam practice test features? Want to lear more about Microsoft Designing and Implementing Microsoft Azure Networking Solutions certification experience? Study Tested Microsoft AZ-700 answers to Most recent AZ-700 questions at Examcollection. Gat a success with an absolute guarantee to pass Microsoft AZ-700 (Designing and Implementing Microsoft Azure Networking Solutions) test on your first attempt.

Free demo questions for Microsoft AZ-700 Exam Dumps Below:

NEW QUESTION 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
* A virtual network named Vnet1
* A subnet named Subnet1 in Vnet1
* A virtual machine named VM1 that connects to Subnet1
* Three storage accounts named storage1, storage2. and storage3
You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other storage accounts.
Solution: You create a network security group (NSG). You configure a service tag for MicrosoftStorage and link the tag to Subnet1.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

NEW QUESTION 2

You have an Azure Front Door instance that provides access to a web app. The web app uses a hostname of www.contoso.com.
You have the routing rules shown in the following table.
AZ-700 dumps exhibit
Which rule will apply to each incoming request? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point
AZ-700 dumps exhibit


Solution:
Table Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-route-matching

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 3

You have an Azure Web Application Firewall (WAF) policy in prevention mode that is associated to an Azure Front Door instance.
You need to configure the policy to meet the following requirements:
AZ-700 dumps exhibit Log all connections from Australia.
AZ-700 dumps exhibit Deny all connections from New Zealand.
AZ-700 dumps exhibit Deny all further connections from a network of 131.107.100.0/24 if there are more than 100 connections during one minute.
What is the minimum number of objects you should create?

  • A. three custom rules that each has one condition
  • B. one custom rule that has three conditions
  • C. one custom rule that has one condition
  • D. one rule that has two conditions and another rule that has one condition

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/afds-overview

NEW QUESTION 4

You have an Azure virtual network and an on-premises datacenter.
You need to implement a Site-to-Site VPN connection between the datacenter and the virtual network. Which two resources should you create? Each correct answer presents part of the solution. NOTE: Each
correct selection is worth one point.

  • A. a virtual network gateway
  • B. Azure Firewall
  • C. a local network gateway
  • D. Azure Web Application Firewall (WAF)
  • E. an on-premises data gateway
  • F. an Azure application gateway
  • G. a user-defined route

Answer: CG

NEW QUESTION 5

You have an Azure environment shown in the following exhibit.
AZ-700 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
AZ-700 dumps exhibit


Solution:
Graphical user interface, text, application Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-peering-gateway-transit?toc=/azure/virtual-ne https://docs.microsoft.com/en-ca/azure/virtual-network/ip-services/ipv6-overview#capabilities

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 6

You have 10 Azure App Service instances. Each instance hosts the same web app. Each instance is in a different Azure region.
You need to configure Azure Traffic Manager to direct users to the instance that has the lowest latency. Which routing method should you use?

  • A. geographic
  • B. weighted
  • C. performance
  • D. priority

Answer: D

NEW QUESTION 7

You have the Azure App Service app shown in the App Service exhibit.
AZ-700 dumps exhibit
The VNet Integration settings for as12 are configured as shown in the Vnet Integration exhibit.
AZ-700 dumps exhibit
The Private Endpoint connections settings for as12 are configured as shown in the Private Endpoint connections exhibit.
AZ-700 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
AZ-700 dumps exhibit


Solution:
Graphical user interface, text, application Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/app-service/web-sites-integrate-with-vnet

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 8

You have the Azure Traffic Manager profiles shown in the following table.
AZ-700 dumps exhibit
You plan to add the endpoints shown in the following table.
AZ-700 dumps exhibit
Which endpoints can you add to Profile2?

  • A. Endpoint1 and Endpoint4 only
  • B. Endpoint1, Endpoint2, Endpoint3, and Endpoint4
  • C. Endpoint1 only
  • D. Endpoint2 and Endpoint3 only
  • E. Endpoint3 only

Answer: A

NEW QUESTION 9

You fail to establish a Site-to-Site VPN connection between your company's main office and an Azure virtual network.
You need to troubleshoot what prevents you from establishing the IPsec tunnel. Which diagnostic log should you review?

  • A. IKEDiagnosticLog
  • B. GatewayDiagnosticLog
  • C. TunnelDiagnosticLog
  • D. RouteDiagnosticLog

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/troubleshoot-vpn-with-azure-diagnostics IKEDiagnosticLog = The IKEDiagnosticLog table offers verbose debug logging for IKE/IPsec. This is very
useful to review when troubleshooting disconnections, or failure to connect VPN scenarios.
GatewayDiagnosticLog = Configuration changes are audited in the GatewayDiagnosticLog table. TunnelDiagnosticLog = The TunnelDiagnosticLog table is very useful to inspect the historical connectivity
statuses of the tunnel.
RouteDiagnosticLog = The RouteDiagnosticLog table traces the activity for statically modified routes or routes received via BGP.
P2SDiagnosticLog = The last available table for VPN diagnostics is P2SDiagnosticLog. This table traces the activity for Point to Site.
https://docs.microsoft.com/en-us/azure/vpn-gateway/troubleshoot-vpn-with-azure-diagnostics

NEW QUESTION 10

You have a website that uses an FQDN of www.contoso.com. The DNS record tor www.contoso.com resolves to an on-premises web server.
You plan to migrate the website to an Azure web app named Web1. The website on Web1 will be published by using an Azure Front Door instance named ContosoFD1.
You build the website on Web1.
You plan to configure ContosoFD1 to publish the website for testing.
When you attempt to configure a custom domain for www.contoso.com on ContosoFD1, you receive the error message shown in the exhibit.
AZ-700 dumps exhibit
You need to test the website and ContosoFD1 without affecting user access to the on-premises web server. Which record should you create in the contoso.com DNS domain?

  • A. a CNAME record that maps www.contoso.com to ContosoFD1.azurefd.net
  • B. a CNAME record that maps www.contoso.com to Web1.contoso.com
  • C. a CNAME record that maps afdverify.www.contoso.com to ContosoFD1.azurefd.net
  • D. a CNAME record that maps afdverify.www.contoso.com to afdverify.ContosoFD1.azurefd.net

Answer: A

NEW QUESTION 11

You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements.
Which two actions should you include in the solution? Each correct answer presents part of the solution.

  • A. On the peerings from Vnet2 and Vnet3, select Use remote gateways.
  • B. On the peering from Vnet1, select Allow forwarded traffic.
  • C. On the peering from Vnet1, select Use remote gateways.
  • D. On the peering from Vnet1, select Allow gateway transit.
  • E. On the peerings from Vnet2 and Vnet3, select Allow gateway transit.

Answer: BD

NEW QUESTION 12

You have three on-premises sites. Each site has a third-party VPN device.
You have an Azure virtual WAN named VWAN1 that has a hub named Hub1. Hub1 connects two of the three on-premises sites by using a Site-to-Site VPN connection.
You need to connect the third site to the other two sites by using Hub1.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
AZ-700 dumps exhibit


Solution:
Table Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-site-to-site-portal

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 13

You have an Azure subscription that contains the following resources:
AZ-700 dumps exhibit A virtual network named Vnet1
AZ-700 dumps exhibit Two subnets named subnet1 and AzureFirewallSubnet
AZ-700 dumps exhibit A public Azure Firewall named FW1
AZ-700 dumps exhibit A route table named RT1 that is associated to Subnet1
AZ-700 dumps exhibit A rule routing of 0.0.0.0/0 to FW1 in RT1
After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machines were activated.
You need to ensure that the virtual machines can be activated. What should you do?

  • A. On FW1, create an outbound service tag rule for AzureCloud.
  • B. On FW1, create an outbound network rule that allows traffic to the Azure Key Management Service (KMS).
  • C. Deploy a NAT gateway.
  • D. To Subnetl, associate a network security group (NSG) that allows outbound access to port 1688.

Answer: B

Explanation:
Reference:
https://ryanmangansitblog.com/2020/05/11/firewall-considerations-windows-virtual-desktop-wvd/

NEW QUESTION 14

Your company has offices in Montreal. Seattle, and Paris. The outbound traffic from each office originates from a specific public IP address.
You create an Azure Front Door instance named FD1 that has Azure Web Application Firewall (WAF) enabled. You configure a WAF policy named Policy! that has a rule named Rule1. Rule1 applies a rate limit of 100 requests for traffic that originates from the office in Montreal.
You need to apply a rate limit of 100 requests for traffic that originates from each office. What should you do?

  • A. Modify the conditions of Rule1.
  • B. Create two additional associations.
  • C. Modify the rule type of Rule1.
  • D. Modify the rate limit threshold of Rule1.

Answer: B

NEW QUESTION 15

You have an Azure Front Door instance that has a single frontend named Frontend1 and an Azure Web Application Firewall (WAF) policy named Policy1. Policy1 redirects requests that have a header containing "string1" to https://www.contoso.com/redirect1. Policy1 is associated to Frontend1.
You need to configure additional redirection settings. Requests to Frontend1 that have a header containing "string2" must be redirected to https://www.contoso.com/redirect2.
Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. Create a custom rule.
  • B. Configure a managed rule.
  • C. Create a frontend host.
  • D. Create a policy.
  • E. Create an association.
  • F. Add a custom rule to Policy1.

Answer: ABE

NEW QUESTION 16

You are implementing the virtual network requirements for VM Analyze.
What should you include in a custom route that is linked to Subnet2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-700 dumps exhibit


Solution:
Graphical user interface, text, application Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 17

You need to meet the network security requirements for the NSG flow logs.
Which type of resource do you need, and how many instances should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-700 dumps exhibit


Solution:
AZ-700 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 18

You have an Azure virtual network named Vnet1 that hosts an Azure firewall named FW1 and 150 virtual machines. Vnet1 is linked to a private DNS zone named contoso.com. All the virtual machines have their name registered in the contoso.com zone.
Vnet1 connects to an on-premises datacenter by using ExpressRoute.
You need to ensure that on-premises DNS servers can resolve the names in the contoso.com zone. Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. On the on-premises DNS servers, configure forwarders that point to the frontend IP address of FW1.
  • B. On the on-premises DNS servers, configure forwarders that point to the Azure provided DNS service at 168.63.129.16.
  • C. Modify the DNS server settings of Vnet1.
  • D. For FW1, enable DNS proxy.
  • E. For FW1, configure a custom DNS server.

Answer: AC

NEW QUESTION 19

You have two Azure virtual networks named Vnet1 and Vnet2 in an Azure region that has three availability zones.
You deploy 12 virtual machines to each virtual network, deploying four virtual machines per zone. The virtual machines in Vnet1 host an app named App1. The virtual machines in Vnet2 host an app named App2.
You plan to use Azure Virtual Network NAT to implement outbound connectivity for App1 and App2. You need to identify the minimum number of subnets and Virtual Network NAT instances required to meet
the following requirements:
• A failure of two zones must NOT affect the availability of either App1 or App2.
• A failure of two zones must NOT affect the outbound connectivity of either Appl1or App2. What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
AZ-700 dumps exhibit


Solution:
AZ-700 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 20
......

Recommend!! Get the Full AZ-700 dumps in VCE and PDF From Downloadfreepdf.net, Welcome to Download: https://www.downloadfreepdf.net/AZ-700-pdf-download.html (New 105 Q&As Version)