Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Microsoft Microsoft Certified: Azure Network Engineer Associate AZ-700 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

You need to implement outbound connectivity for VMScaleSet1. The solution must meet the virtual networking requirements and the business requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 31


Expert Solution
Questions # 32:

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.


Expert Solution
Questions # 33:

You have an Azure virtual network that contains a subnet named Subnet1. Subnet1 is associated to a network security group (NSG) named NSG1. NSG1 blocks all outbound traffic that is not allowed explicitly.

Subnet1 contains virtual machines that must communicate with the Azure Cosmos DB service.

You need to create an outbound security rule in NSG1 to enable the virtual machines to connect to Azure Cosmos DB.

What should you include in the solution?

Options:

A.

a service tag


B.

a private endpoint


C.

a subnet delegation


D.

an application security group


Expert Solution
Questions # 34:

You have an Azure subscription that is linked to an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. The subscription contains the following resources:

* An Azure App Service app named App1

* An Azure DNS zone named contoso.com

* An Azure private DNS zone named private.contoso.com

* A virtual network named Vnet1

You create a private endpoint for App1. The record for the endpoint is registered automatically in Azure DNS.

You need to provide a developer with the name that is registered in Azure DNS for the private endpoint.

What should you provide?

Options:

A.

app1.privatelink.azurewebsites.net


B.

app1.contoso.com


C.

app1.contoso.onmicrosoft.com


D.

app1.private.contoso.com


Expert Solution
Questions # 35:

You have an Azure subscription that contains the resources shown in the following table.

Question # 35

You need to ensure that VM1 and VM2 can connect only to storage1. The solution must meet the following requirements:

• Prevent VM1 and VM2 from accessing any other storage accounts.

• Ensure that storage1 is accessible from the internet.

What should you use?

Options:

A.

a network security group (NSG)


B.

a private endpoint


C.

a private link


D.

a service endpoint policy


Expert Solution
Questions # 36:

You have an Azure subscription that contains an Azure Firewall Premium policy named FWP1.

To FWP1, you plan to add the rule collections shown in the following table.

Which priority should you assign to each rule collection? To answer, drag the appropriate priority values to the correct rule collections- Each value may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 36


Expert Solution
Questions # 37:

You have an Azure subscription that contains an Azure Front Door Premium profile named AFD1 and an Azure Web Application Firewall (WAF) policy named WAF1. AFD1 is associated with WAF1.

You need to configure a rate limit for incoming requests to AFD1.

Solution: You add a rule to the rule set of AFD1.

Does this meet the goal?

Options:

A.

Yes


B.

No


Expert Solution
Questions # 38:

You have an Azure subscription that contains a virtual machine named VM1 and a virtual network named Vnet1. Vnet1 contains three subnets named Subnet1, Subnet2 and GatewaySubnet. VM1 is connected to Subnet 1.

You plan to deploy a new virtual machine named VM2 that will perform network traffic routing and inspection.

You need to ensure that all the traffic from VM1 to the internet will be routed through VM2.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 38


Expert Solution
Questions # 39:

You have an Azure Virtual Desktop deployment that has 500 session hosts.

All outbound traffic to the internet uses a NAT gateway.

During peak business hours, some users report that they cannot access internet resources. In Azure Monitor, you discover many failed SNAT connections.

You need to increase the available SNAT connections.

What should you do?

Options:

A.

Add a public IP address.


B.

Bind the NAT gateway to another subnet.


C.

Deploy Azure Standard Load Balancer that has outbound rules.


Expert Solution
Questions # 40:

You have two Azure subscriptions named Sub1 and Sub2 that contain the resources shown in the following table.

Question # 40

VNet1 and VNet2 are NOT connected.

You plan to create an Azure Private Link service named Link1 that will be used to connect VNet1 and VNet2. You need to ensure that Link1 meets the following requirements:

• Ensures that VM1 can connect only to a web app hosted on VM2

• Prevents VM1 from connecting to the other resources that are connected to VNet2

Which additional resources should you create for each virtual network? To answer, drag the appropriate resources to the correct virtual networks. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 40


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions