Pass the Microsoft Microsoft Certified: Azure Network Engineer Associate AZ-700 Questions and answers with CertsForce

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

You need to configure a custom rule for APPGWI-WAFPolicy to allow only connections that originate from FD1. The solution must support the planned changes.

Which Match type and Match variable should you select?

Options:

A.

String and RequestCookies


B.

IP address and RemoteAddr


C.

String and RequestHeaders


D.

Geo location and RemoteAddr


Expert Solution
Questions # 42:

You ate configuring the DNS forwarding luleset for DNSR1

You need to configure the destination IP address for azure.proseware.com and for corp.proseware.com. The solution must meet the general requirements.

Which IP addiesses should you configure for each namespace? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 42


Expert Solution
Questions # 43:

You need to plan the deployment of LBGW1. The solution must support the planned changes.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 43


Expert Solution
Questions # 44:

You need to manage connectivity from NYCNet to the Azure services that use private endpoints. The solution must meet the security requirements. What should you do first?

Options:

A.

Add a route table to SUBNET-PL


B.

Enable a network policy for SUBNET-PE.


C.

From Azure Virtual Network Manager, create a security admin configuration.


D.

From Azure Viitual Network Manager, create a network group that has Member type set to Subnet


Expert Solution
Questions # 45:

You need to configure FD1 to provide user access to app2.proseware.com. The solution must meet the security requirements and the general requirements.

What should you do first?

Options:

A.

Add a custom domain to FD1.


B.

Add a security policy to FD1.


C.

Request a certificate from a trusted root CA.


D.

Export the TLS certificate and the private key from App2.


Expert Solution
Questions # 46:

You need to configure a security rule for APPGW1-NSG1. The solution must support the planned changes. Which service tag should you use?

Options:

A.

AzureFrontDoor.FirstParty


B.

AzureFrontDoor.Infra


C.

AzureFrontDoor.Backend


D.

AzureFrontDoor.Frontend


Expert Solution
Questions # 47:

You need to configure APPGW1 to support end-to-end encryption. The solution must meet the security requirements. What should you do?

Options:

A.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA and includes the full certificate chain.


B.

From the Backend settings, upload a wildcard TLS certificate that has a private key issued by the internal root CA


C.

From the Backend settings, upload the internal root CA certificate.


D.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA.


Expert Solution
Questions # 48:

What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?

Options:

A.

a private endpoint


B.

a virtual network peering


C.

a private link service


D.

a routing table


E.

a service endpoint


Expert Solution
Questions # 49:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 49


Expert Solution
Questions # 50:

You need to meet the network security requirements for the NSG flow logs.

Which type of resource do you need, and how many instances should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 50


Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions