Weekend Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

AZ-700 Questions and Answers

Question # 6

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 7

You are implementing the Virtual network requirements for Vnet6.

What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 8

You need to configure GW1 to meet the network security requirements for the P2S VPN users.

Which Tunnel type should you select in the Point-to-site configuration settings of GW1?

A.

IKEv2 and OpenVPN (SSL)

B.

IKEv2

C.

IKEv2 and SSTP (SSL)

D.

OpenVPN (SSL)

E.

SSTP (SSL)

Full Access
Question # 9

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 10

What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?

A.

a private endpoint

B.

a virtual network peering

C.

a private link service

D.

a routing table

E.

a service endpoint

Full Access
Question # 11

You create NSG10 and NSG11 to meet the network security requirements.

For each of the following statements, select Yes it the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 12

You need to configure the P2S VPN to meet the connectivity requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 13

You need to plan the deployment of LBGW1. The solution must support the planned changes.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 14

You need to configure FD1 to provide user access to app2.proseware.com. The solution must meet the security requirements and the general requirements.

What should you do first?

A.

Add a custom domain to FD1.

B.

Add a security policy to FD1.

C.

Request a certificate from a trusted root CA.

D.

Export the TLS certificate and the private key from App2.

Full Access
Question # 15

You need to configure APPGW1 to support end-to-end encryption. The solution must meet the security requirements. What should you do?

A.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA and includes the full certificate chain.

B.

From the Backend settings, upload a wildcard TLS certificate that has a private key issued by the internal root CA

C.

From the Backend settings, upload the internal root CA certificate.

D.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA.

Full Access
Question # 16

You need to configure connectivity between NYCNet and SFONet. The solution must meet the connectivity requirements. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Full Access
Question # 17

You ate configuring the DNS forwarding luleset for DNSR1

You need to configure the destination IP address for azure.proseware.com and for corp.proseware.com. The solution must meet the general requirements.

Which IP addiesses should you configure for each namespace? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 18

You need to deploy Azure Virtual Network Manager. The solution must support the planned changes and meet the connectivity requirements.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 19

You need to configure a custom rule for APPGWI-WAFPolicy to allow only connections that originate from FD1. The solution must support the planned changes.

Which Match type and Match variable should you select?

A.

String and RequestCookies

B.

IP address and RemoteAddr

C.

String and RequestHeaders

D.

Geo location and RemoteAddr

Full Access
Question # 20

You need to identify which IP address space to allocate for the planned deployment of PRDNS1 to HubVNet and SpokeVNet. The solution must meet the general requirements

What should you identify for each virtual network? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Full Access
Question # 21

You need to manage connectivity from NYCNet to the Azure services that use private endpoints. The solution must meet the security requirements. What should you do first?

A.

Add a route table to SUBNET-PL

B.

Enable a network policy for SUBNET-PE.

C.

From Azure Virtual Network Manager, create a security admin configuration.

D.

From Azure Viitual Network Manager, create a network group that has Member type set to Subnet

Full Access
Question # 22

You need to configure a security rule for APPGW1-NSG1. The solution must support the planned changes. Which service tag should you use?

A.

AzureFrontDoor.FirstParty

B.

AzureFrontDoor.Infra

C.

AzureFrontDoor.Backend

D.

AzureFrontDoor.Frontend

Full Access
Question # 23

You have an Azure subscription that contains the resources shown in the following table.

Gateway1 provides access to App1 by using a URL of http://app1.contoso.com.

You create a new web app named App2.

You need to configure Gateway1 to enable minimize administrative effort.

What should you configure on Gateway1?

A.

a backend pool and a routing

B.

a listener and a routing rule

C.

a listener, a backend pool, and a rule

D.

a listener and a backend pool

Full Access
Question # 24

You have an Azure subscription that contains an ExpressRoute Standard gateway named GW1.

You need to upgrade GW1 to support ExpressRoute FastPath. The solution must minimize downtime.

Which SKU should you use?

A.

ErGw3AZ

B.

ErGw2AZ

C.

High performance

D.

Ultra performance

Full Access
Question # 25

Azure virtual networks in the East US Azure region as shown in the following table.

The virtual networks are peered to one another. Each virtual network contains four subnets.

You plan to deploy a virtual machine named VM1 that will inspect and route traffic between all the subnets on both the virtual networks.

What is the minimum number of IP addresses that you must assign to VM1?

A.

1

B.

2

C.

4

D.

8

Full Access
Question # 26

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains the following subnets.

• AzureFirewallSubnet

• GatewaySubnet

• Subnet 1

• Subnet2

• Subnet3

Subnet2 has a delegation to the Microsoft.Web/serverfarms service. The subscription contains the resources shown in the following table.

You need to implement an Azure application gateway named AG1 that will be integrated with an Azure Web Application Firewall (WAF). AG1 will be used to publish VMSS1.

To which subnet should you connect AG1?

A.

Subrwt2

B.

Subnet 1

C.

Subnet3

D.

AzureFjrewall Subnet

E.

GatewaySubnet

Full Access
Question # 27

You have the Azure resources shown in the following table.

You need to link VNei2 to Circuit1

What should you create in each subscription? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 28

O: 27 HOTSPOT

You have an Azure subscription that contains the resources shown in the following table.

You plan to deploy an app named App1 to meet the following requirements.

• External users must be able to access App1 from the internet.

• App1 will be load balanced across all the virtual machines.

• App1 will be hosted on VM1, VM2. VM3. and VM4.

• App1 must be available if an Azure region fails.

• Costs must be minimized.

You need to implement a global load balancer solution for App.

What should you configure? To answer, select the appropriate options in the answer area

NOTE: Bach correct answer is worth one point.

Full Access
Question # 29

You have an Azure subscription that contains multiple virtual machines in the West US Azure region.

You need to use Traffic Analytics.

Which two resources should you create? Each correct answer presents part of the solution. (Choose two.)

NOTE: Each correct answer selection is worth one point.

A.

an Azure Monitor workbook

B.

a Log Analytics workspace

C a storage account

C.

an Azure Sentinel workspace

D.

an Azure Monitor data collection rule

Full Access
Question # 30

You have an Azure subscription that contains the resources shown in the following table.

You discover that users connect directly to App1.

You need to meet The following requirements:

• Administrators must only access App1 by using a private endpoint.

• All user connections to App1 must be routed through FD1.

• The downtime of connections to App1 must be minimized.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.

Full Access
Question # 31

You have two on-premises datacenters.

You have an Azure subscription that contains four virtual networks named VNet1 VNet2, VNet3, and VNet4

You create an Azure virtual WAN named VWAN1. VWAN1 contains a single virtual hub that is connected to both on-premises datacenters and all the virtual networks in a full mesh topology.

You create a route table named RT1.

You need to configure VWAN1 to meet the following requirements:

• Connectivity between VNet1 and VNet2 and both on-premises datacenters must be allowed.

• Connectivity between VNet3 and VNet4 and both on-premises datacenters must be allowed.

• VNet1 and VNet2 must be isolated from VNet3 and VNet4.

How should you configure routing for VNet1 and VNet2 and for both on-premises datacenters? To answer, drag the appropriate route tables and route table propagation to the correct requirements. Each route table and route table propagation may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Full Access
Question # 32

You plan to configure BGP for a Site-to-Site VPN connection between a datacenter and Azure.

Which two Azure resources should you configure? Each correct answer presents a part of the solution. (Choose two.)

NOTE: Each correct selection is worth one point.

A.

a virtual network gateway

B.

Azure Application Gateway

C.

Azure Firewall

D.

a local network gateway

E.

Azure Front Door

Full Access
Question # 33

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have two Azure virtual networks named Vnet1 and Vnet2.

You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.

You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit. Vnet2 can use the remote gateway.

You discover that Client1 cannot communicate with Vnet2.

You need to ensure that Client1 can communicate with Vnet2.

Solution: You enable BGP on the gateway of Vnet1.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 34

You have an Azure subscription that contains a virtual network named VNet1 and the virtual machines shown in the following table.

All the virtual machines are connected to VNet1.

You need to ensure that the applications hosted on the virtual machines can be accessed from the internet. The solution must ensure that the virtual machines share a single public IP address

What should you use?

A.

a NAT gateway

B.

an internal load balancer

C.

a public load balancer

D.

Azure Application Gateway

Full Access
Question # 35

Task 7

You need to ensure that hosts on VNET2 can access hosts on both VNET1 and VNET3. The solution must prevent hosts on VNET1 and VNET3 from communicating through VNET2.

Full Access
Question # 36

You have an Azure subscription that contains the resources shown in the following table.

You need to ensure that VM1 and VM2 can connect only to storage1. The solution must meet the following requirements:

• Prevent VM1 and VM2 from accessing any other storage accounts.

• Ensure that storage1 is accessible from the internet.

What should you use?

A.

a network security group (NSG)

B.

a private endpoint

C.

a private link

D.

a service endpoint policy

Full Access
Question # 37

You have an Azure subscription that contains an Azure key vault named Vaultl and an app registration for an Azure AD app named App1.

You have a DNS domain named contoso.com that is hosted by a third-party DNS provider.

You plan to deploy App1 by using Azure App Service. App1 will have the following configurations:

• App1 will be hosted across five App Service apps.

• Users will access App1 by using a URL of https://app1.contoso.com.

• The user traffic of App1 will be managed by using Azure Front Door.

• The traffic between Front Door and the App Service apps will be sent by using HTTP.

• App1 will be secured by using an SSL certificate from a third-party certificate authority (CA).

You need to support the Front Door deployment.

Which two DNS records should you create, and to where should you import the SSL certificate for App1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 38

You have an on-premises network.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 is connected to an Azure Virtual WAN hub named Hub1.

You need to enable connectivity between the on-premises network and VNet1 by using Hub1.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 39

You have an Azure subscription.

You have the on-premises sites shown the following table.

You plan to deploy Azure Virtual WAN.

You are evaluating Virtual WAN Basic and Virtual WAN Standard.

Which type of Virtual WAN can you use for each site? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 40

You have the resources shown in the following table.

From the Microsoft Entra admin center, you register the Azure VPN application as an enterprise application.

You need to enable Microsoft Entra authentication for the P2S VPN connections. The solution must meet the following requirements;

• Ensure that only the members of Group1 can establish VPN connections to VPNGW1.

• Ensure that only the members of Group2 can establish VPN connections to VPNGW2.

In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 41

You need to connect an on-premises network and an Azure environment. The solution must use ExpressRoute and support failing over to a Site-to-Site VPN connection if there is an ExpressRoute failure.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 42

NO: 6 HOTSPOT

You have an Azure application gateway named AppGW1 that provides access to the following hosts:

* www.adatum.com

* www.contoso.com

* www.fabrikam.com

AppGW1 has the listeners shown in the following table.

You create Azure Web Application Firewall (WAF) policies for AppGW1 as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 43

Your company has a single on-premises datacenter in New York. The East US Azure region has a peering location in New York.

The company only has Azure resources in the East US region.

You need to implement ExpressRoute to support up to 1 Gbps. You must use only ExpressRoute Unlimited data plans. The solution must minimize costs.

Which type of ExpressRoute circuits should you create?

A.

ExpressRoute Local

B.

ExpressRoute Direct

C.

ExpressRoute Premium

D.

ExpressRoute Standard

Full Access
Question # 44

You plan to publish a website that will use an FQDN of www.contoso.com. The website will be hosted by using the Azure App Service apps shown in the following table.

You plan to use Azure Traffic Manager to manage the routing of traffic for www.contoso.com betw een AS1 and AS2.

You need to ensure that Traffic Manager routes traffic for www.contoso.com.

Which DNS record should you create?

A.

two A records that map wmv.contoso.com to 131 107 100 1 and 131 107 200 1

B.

a CNAME record that maps www.contoso.com to TMprofile1.azurefd.net

C.

a CNAME record that mapswww.contoso.comtoTMprofile1.trafficmanager.net

D.

a TXT record that contains a string ofas1.contoso.com and as2.contoso.com in the details

Full Access