Microsoft

AZ-700 Free Practice Questions — Page 17

Question 172

You plan to implement an Azure virtual network that will contain 10 virtual subnets. The subnets will use IPv6 addresses. Each subnet will host up to 200 load-balanced virtual machines. You need to recommend which subnet mask size to use for the virtual subnets. What should you recommend?

A. /64
B. /120
C. /48
D. /24
Show Answer
Correct Answer: A
Explanation:
In Azure, IPv6 subnets must be exactly /64 in size. This is a platform requirement, not a capacity calculation. A /64 subnet is mandatory for IPv6 virtual network subnets to ensure compatibility with IPv6 features such as SLAAC and routing to on‑premises networks. The number of VMs (200 per subnet) is irrelevant because a /64 provides an extremely large address space. Other options like /120, /48, or /24 are not supported for Azure IPv6 subnets.

Question 173

HOTSPOT - You have an Azure subscription that contain a storage account named st1 in the East US Azure region. You have the virtual networks shown in the following table. You have the subnets shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for AZ-700 question 173 Illustration for AZ-700 question 173 Illustration for AZ-700 question 173
Show Answer
Correct Answer: No Yes No
Explanation:
1) Azure Bastion must be deployed in a dedicated subnet named AzureBastionSubnet (/26 or larger), not an existing workload subnet. 2) A /25 subnet has 128 addresses; after Azure reservations and existing VMs, sufficient IPs remain for 100 more VMs. 3) 10.3.1.0/16 is an invalid subnet (not aligned to /16) and subnets with existing resources cannot be expanded to an invalid range.

Question 174

You have an Azure subscription that contains a virtual network named VNet1. You deploy several web apps and configure the apps to use private endpoints on VNet1. You need to identify which DNS records the web apps registered automatically. Where will the records be created?

A. an Azure DNS zone named privatelink.azurewebsites.net
B. an Azure Private DNS zone named azurewebsites.net
C. an Azure Private DNS zone named privatelink.azurewebsites.net
D. an Azure DNS zone named azurewebsites.net
Show Answer
Correct Answer: C
Explanation:
When Azure App Service web apps are configured with Private Endpoints, Azure automatically creates DNS records in an Azure **Private DNS zone** specific to the service. For App Service, this zone is **privatelink.azurewebsites.net**. The private endpoint integration either links to an existing zone with this name or creates it automatically, and the web apps register their private IP records there.

Question 175

HOTSPOT - You have the Azure resources shown in the following table. You need to link VNet2 to Circuit1. What should you create in each subscription? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-700 question 175 Illustration for AZ-700 question 175
Show Answer
Correct Answer: Sub1: An ExpressRoute circuit connection authorization Sub2: An ExpressRoute circuit connection
Explanation:
Circuit1 is owned in Sub1, so Sub1 must create an authorization to allow another subscription to use it. Sub2, which hosts VNet2 and Gateway2, uses that authorization to create the ExpressRoute circuit connection to Circuit1.

Question 176

You have 10 on-premises networks that are connected by using a 3rd party Software Defined Wide Area Network (SD-WAN) solution. You have an Azure subscription that contains five virtual networks. You plan to connect the Azure virtual networks and the on-premises networks by using an Azure Virtual WAN with a single virtual WAN hub. You need to ensure that the Azure Virtual WAN can act as a node in the 3rd party SD-WAN solution. What should you include in the solution?

A. An Azure Virtual WAN ExpressRoute gateway
B. A Network Virtual Appliance (NVA)
C. A Site to site gateway (VPN gateway)
D. A Point to site gateway (User VPN gateway)
Show Answer
Correct Answer: B
Explanation:
To make Azure Virtual WAN participate as a node in a third‑party SD‑WAN, you must deploy a Network Virtual Appliance (NVA) in the Virtual WAN hub. NVAs are supported for direct integration with third‑party SD‑WAN solutions, allowing the SD‑WAN control and data planes to extend into Azure. ExpressRoute and VPN gateways provide connectivity but do not allow Azure Virtual WAN to act as an SD‑WAN node, and Point‑to‑Site gateways are for individual user access only.

Question 177

You have three on-premises networks. You have an Azure subscription that contains a Basic Azure virtual WAN. The virtual WAN contains a single virtual hub and a virtual network gateway that is limited to a throughput of 1 Gbps. The on-premises networks connect to the virtual WAN by using Site-to-Site (S2S) VPN connections. You need to increase the throughput of the virtual WAN to 3 Gbps. The solution must minimize administrative effort. What should you do?

A. Upgrade the virtual WAN to the Standard SKU.
B. Add an additional VPN gateway to the Azure subscription.
C. Create an additional virtual hub.
D. Increase the number of gateway scale units.
Show Answer
Correct Answer: A
Explanation:
A Basic Azure virtual WAN has a Site-to-Site VPN gateway throughput limit of about 1 Gbps and does not support increasing gateway scale units to raise throughput. Increasing scale units is only applicable once the virtual WAN supports higher-capacity gateways. To reach 3 Gbps with minimal administrative effort, you must upgrade the virtual WAN to the Standard SKU, which supports higher throughput VPN gateways.

Question 178

HOTSPOT - You have an Azure subscription. You plan to use Azure Virtual WAN. You need to deploy a virtual WAN hub that meets the following requirements: • Supports 4 Gbps of Site-to-Site (S2S) VPN traffic • Supports 8 Gbps of ExpressRoute traffic • Minimizes costs How many scale units should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-700 question 178
Show Answer
Correct Answer: S2S VPN gateway: 8 scale units ExpressRoute gateway: 4 scale units
Explanation:
In Azure Virtual WAN, one S2S VPN scale unit supports ~500 Mbps, so 4 Gbps requires 4,000 / 500 = 8 units. One ExpressRoute scale unit supports ~2 Gbps, so 8 Gbps requires 8 / 2 = 4 units. These are the minimum units to meet throughput while minimizing cost.

Question 179

DRAG DROP - You have an on-premises network. You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an ExpressRoute gateway. You need to connect VNet1 to the on-premises network by using an ExpressRoute circuit. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for AZ-700 question 179
Show Answer
Correct Answer: Create the ExpressRoute circuit. Send a service key to your connectivity provider. Configure Azure private peering. Create a connection from VNet1 to the ExpressRoute circuit.
Explanation:
An ExpressRoute circuit must exist first. The service key is then provided to the connectivity provider for provisioning. After the circuit is provisioned, Azure private peering is configured. Finally, the virtual network gateway is linked to the ExpressRoute circuit.

Question 181

Case Study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question. Overview - Litware, Inc. is a financial company that has a main datacenter in Boston and 20 branch offices across the United States. Users have Android, iOS, and Windows 10 devices. Existing Environment - Hybrid Environment - The on-premises network contains an Active Directory forest named litwareinc.com that syncs to an Azure Active Directory (Azure AD) tenant named litwareinc.com by using Azure AD Connect. All offices connect to a virtual network named Vnet1 by using a Site-to-Site VPN connection. Azure Environment - Litware has an Azure subscription named Sub1 that is linked to the litwareinc.com Azure AD tenant. Sub1 contains resources in the East US Azure region as shown in the following table. A diagram of the resource in the East US Azure region is shown in the Azure Network Diagram exhibit. There is bidirectional peering between Vnet1 and Vnet2. There is bidirectional peering between Vnet1 and Vnet3. Currently, Vnet2 and Vnet3 cannot communicate directly. Azure Network Diagram - Requirements - Business Requirements - Litware wants to minimize costs whenever possible, as long as all other requirements are met. Virtual Networking Requirements - Litware identifies the following virtual networking requirements: • Direct the default route of 0.0.0.0/0 on Vnet2 and Vnet3 to the Boston datacenter over an ExpressRoute circuit. • Ensure that the records in the cloud.litwareinc.com can be resolved from the on-premises locations. • Automatically register the DNS names of Azure virtual machines to the cloud.litwareinc.com zone. • Minimize the size of the subnets allocated to platform-managed services. • Allow traffic from VMScaleSet1 to VMScaleSet2 on the TCP port 443 only. Hybrid Networking Requirements - Litware identifies the following hybrid networking requirements: • Users must be able to connect to Vnet1 by using a Point-to-Site (P2S) VPN when working remotely. Connections must be authenticated by Azure AD. • Latency of the traffic between the Boston datacenter and all the virtual networks must be minimized. • The Boston datacenter must connect to the Azure virtual networks by using an ExpressRoute FastPath connection. • Traffic between Vnet2 and Vnet3 must be routed through Vnet1. PaaS Networking Requirements - Litware identifies the following networking requirements for platform as a service (PaaS): • The storage1 account must be accessible from all on-premises locations without exposing the public endpoint of storage1. • The storage2 account must be accessible from Vnet2 and Vnet3 without exposing the public endpoint of storage2. You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements. Which two actions should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. On the peering from Vnet1, select Allow for Traffic forwarded from remote virtual network.
B. On the peerings from Vnet2 and Vnet3, select Allow for Traffic forwarded from remote virtual network.
C. On the peering from Vnet1, select Use the remote virtual network's gateway or Route Server.
D. On the peering from Vnet1, select Allow for Traffic to remote virtual network.
E. On the peerings from Vnet2 and Vnet3, select Use the remote virtual network's gateway or Route Server.
Show Answer
Correct Answer: B, E
Explanation:
Vnet1 acts as a hub with the gateway. To route traffic between Vnet2 and Vnet3 through Vnet1, the spoke peerings (Vnet2 and Vnet3) must allow forwarded traffic so they can accept traffic that transits Vnet1 (B). Additionally, Vnet2 and Vnet3 must be configured to use the remote virtual network’s gateway in Vnet1 so they can send traffic via the hub gateway (E). Together these settings enable hub-and-spoke transit routing while meeting the cost and networking requirements.

Question 182

HOTSPOT - Case Study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question. Overview - Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas. Contoso recently purchased an Azure subscription and is performing its first pilot project in Azure. Existing Environment - Azure Network Infrastructure - Contoso has an Azure Active Directory (Azure AD) tenant named contoso.com. The Azure subscription contains the virtual networks shown in the following table. Vnet1 contains a virtual network gateway named GW1. Azure Virtual Machines - The Azure subscription contains virtual machines that run Windows Server 2019 as shown in the following table. The NSGs are associated to the network interfaces on the virtual machines. Each NSG has one custom security rule that allows RDP connections from the internet. The firewall on each virtual machine allows ICMP traffic. An application security group named ASG1 is associated to the network interface of VM1. Azure Network Infrastructure Diagram Azure Private DNS Zones - The Azure subscription contains the Azure private DNS zones shown in the following table. Zone1.contoso.com has the virtual network links shown in the following table. Other Azure Resources - The Azure subscription contains additional resources as shown in the following table. Requirements - Virtual Network Requirements - Contoso has the following virtual network requirements: • Create a virtual network named Vnet6 in West US that will contain the following resources and configurations: o Two container groups that connect to Vnet6 o Three virtual machines that connect to Vnet6 o Allow VPN connections to be established to Vnet6 o Allow the resources in Vnet6 to access KeyVault1, DB1, and Vnet1 over the Microsoft backbone network. • The virtual machines in Vnet4 and Vnet5 must be able to communicate over the Microsoft backbone network. • A virtual machine named VM-Analyze will be deployed to Subnet1. VM-Analyze must inspect the outbound network traffic from Subnet2 to the internet. Network Security Requirements - Contoso has the following network security requirements: • Configure Azure Active Directory (Azure AD) authentication for Point-to-Site (P2S) VPN users. • Enable NSG flow logs for NSG3 and NSG4. • Create an NSG named NSG10 that will be associated to Vnet1/Subnet1 and will have the custom inbound security rules shown in the following table. • Create an NSG named NSG11 that will be associated to Vnet1/Subnet2 and will have the custom outbound security rules shown in the following table. You are implementing the virtual network requirements for Vnet6. What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182 Illustration for AZ-700 question 182
Show Answer
Correct Answer: Subnets: 3 Service endpoints: 2
Explanation:
Vnet6 requires three subnets: one delegated subnet for the two container groups, one subnet for the three virtual machines, and one GatewaySubnet to support VPN connections. Container groups (Azure Container Instances) cannot share a subnet with virtual machines but multiple container groups can share the same delegated subnet. To allow access to KeyVault1 and DB1 over the Microsoft backbone network, service endpoints are required for Azure Key Vault and Azure SQL Database, resulting in two service endpoints. Peering handles access to Vnet1 without additional service endpoints.

$19

Get all 344 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.