HOTSPOT
-
You have an Azure subscription.
You plan to use Azure Virtual WAN.
You need to deploy a virtual WAN hub that meets the following requirements:
• Supports 4 Gbps of Site-to-Site (S2S) VPN traffic
• Supports 8 Gbps of ExpressRoute traffic
• Minimizes costs
How many scale units should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: In Azure Virtual WAN, an S2S VPN gateway scale unit provides about 500 Mbps aggregate throughput, so 4 Gbps requires 8 scale units. An ExpressRoute gateway scale unit provides 2 Gbps, so 8 Gbps requires 4 scale units. These are the minimum values that satisfy the requirements.
Question 182
DRAG DROP
-
You have an on-premises network.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an ExpressRoute gateway.
You need to connect VNet1 to the on-premises network by using an ExpressRoute circuit.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Show Answer
Correct Answer: 1. Create the ExpressRoute circuit.
2. Send a service key to your connectivity provider.
3. Configure Azure private peering.
4. Create a connection from VNet1 to the ExpressRoute circuit.
Explanation: Provision the ExpressRoute circuit first, provide the service key so the provider can complete provisioning, configure Azure private peering for VNet connectivity, and finally link the VNet gateway to the ExpressRoute circuit. Azure public peering is not required for this scenario.
Question 184
Case Study -
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.
Overview -
Litware, Inc. is a financial company that has a main datacenter in Boston and 20 branch offices across the United States. Users have Android, iOS, and Windows 10 devices.
Existing Environment -
Hybrid Environment -
The on-premises network contains an Active Directory forest named litwareinc.com that syncs to an Azure Active Directory (Azure AD) tenant named litwareinc.com by using Azure AD Connect.
All offices connect to a virtual network named Vnet1 by using a Site-to-Site VPN connection.
Azure Environment -
Litware has an Azure subscription named Sub1 that is linked to the litwareinc.com Azure AD tenant. Sub1 contains resources in the East US Azure region as shown in the following table.
A diagram of the resource in the East US Azure region is shown in the Azure Network Diagram exhibit.
There is bidirectional peering between Vnet1 and Vnet2. There is bidirectional peering between Vnet1 and Vnet3. Currently, Vnet2 and Vnet3 cannot communicate directly.
Azure Network Diagram -
Requirements -
Business Requirements -
Litware wants to minimize costs whenever possible, as long as all other requirements are met.
Virtual Networking Requirements -
Litware identifies the following virtual networking requirements:
• Direct the default route of 0.0.0.0/0 on Vnet2 and Vnet3 to the Boston datacenter over an ExpressRoute circuit.
• Ensure that the records in the cloud.litwareinc.com can be resolved from the on-premises locations.
• Automatically register the DNS names of Azure virtual machines to the cloud.litwareinc.com zone.
• Minimize the size of the subnets allocated to platform-managed services.
• Allow traffic from VMScaleSet1 to VMScaleSet2 on the TCP port 443 only.
Hybrid Networking Requirements -
Litware identifies the following hybrid networking requirements:
• Users must be able to connect to Vnet1 by using a Point-to-Site (P2S) VPN when working remotely. Connections must be authenticated by Azure AD.
• Latency of the traffic between the Boston datacenter and all the virtual networks must be minimized.
• The Boston datacenter must connect to the Azure virtual networks by using an ExpressRoute FastPath connection.
• Traffic between Vnet2 and Vnet3 must be routed through Vnet1.
PaaS Networking Requirements -
Litware identifies the following networking requirements for platform as a service (PaaS):
• The storage1 account must be accessible from all on-premises locations without exposing the public endpoint of storage1.
• The storage2 account must be accessible from Vnet2 and Vnet3 without exposing the public endpoint of storage2.
You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements.
Which two actions should you include in the solution? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. On the peering from Vnet1, select Allow for Traffic forwarded from remote virtual network.
B. On the peerings from Vnet2 and Vnet3, select Allow for Traffic forwarded from remote virtual network.
C. On the peering from Vnet1, select Use the remote virtual network's gateway or Route Server.
D. On the peering from Vnet1, select Allow for Traffic to remote virtual network.
E. On the peerings from Vnet2 and Vnet3, select Use the remote virtual network's gateway or Route Server.
Show Answer
Correct Answer: A, E
Explanation: In a hub-and-spoke topology, VNet1 acts as the hub with the gateway. To let spoke VNets use the hub gateway for ExpressRoute/VPN transit, enable 'Use the remote virtual network's gateway or Route Server' on the peerings from VNet2 and VNet3 (E). To allow transitive forwarding of traffic between the spokes through the hub, enable forwarded traffic on the hub-side peering (Allow traffic forwarded from remote virtual network) (A).
Question 185
HOTSPOT
-
Case Study
-
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
-
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.
Overview
-
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso recently purchased an Azure subscription and is performing its first pilot project in Azure.
Existing Environment
-
Azure Network Infrastructure
-
Contoso has an Azure Active Directory (Azure AD) tenant named contoso.com.
The Azure subscription contains the virtual networks shown in the following table.
Vnet1 contains a virtual network gateway named GW1.
Azure Virtual Machines
-
The Azure subscription contains virtual machines that run Windows Server 2019 as shown in the following table.
The NSGs are associated to the network interfaces on the virtual machines. Each NSG has one custom security rule that allows RDP connections from the internet. The firewall on each virtual machine allows ICMP traffic.
An application security group named ASG1 is associated to the network interface of VM1.
Azure Network Infrastructure Diagram
Azure Private DNS Zones
-
The Azure subscription contains the Azure private DNS zones shown in the following table.
Zone1.contoso.com has the virtual network links shown in the following table.
Other Azure Resources
-
The Azure subscription contains additional resources as shown in the following table.
Requirements
-
Virtual Network Requirements
-
Contoso has the following virtual network requirements:
• Create a virtual network named Vnet6 in West US that will contain the following resources and configurations:
o Two container groups that connect to Vnet6
o Three virtual machines that connect to Vnet6
o Allow VPN connections to be established to Vnet6
o Allow the resources in Vnet6 to access KeyVault1, DB1, and Vnet1 over the Microsoft backbone network.
• The virtual machines in Vnet4 and Vnet5 must be able to communicate over the Microsoft backbone network.
• A virtual machine named VM-Analyze will be deployed to Subnet1. VM-Analyze must inspect the outbound network traffic from Subnet2 to the internet.
Network Security Requirements
-
Contoso has the following network security requirements:
• Configure Azure Active Directory (Azure AD) authentication for Point-to-Site (P2S) VPN users.
• Enable NSG flow logs for NSG3 and NSG4.
• Create an NSG named NSG10 that will be associated to Vnet1/Subnet1 and will have the custom inbound security rules shown in the following table.
• Create an NSG named NSG11 that will be associated to Vnet1/Subnet2 and will have the custom outbound security rules shown in the following table.
You are implementing the virtual network requirements for Vnet6.
What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Subnets: 3
Service endpoints: 2
Explanation: VNet6 needs a GatewaySubnet for the VPN gateway, one delegated subnet for Azure Container Instances (both container groups can share it), and one subnet for the virtual machines. To access Azure SQL Database (DB1) and Key Vault over the Microsoft backbone using service endpoints, enable the Microsoft.Sql and Microsoft.KeyVault service endpoints.
Question 186
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username:
Azure Password: xxxxxxxxxx
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the
portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You plan to implement an Azure application gateway in the East US Azure region. The
application gateway will have Web Application Firewall (WAF) enabled.
You need to create a policy that can be linked to the planned application gateway. The policy must block connections from IP addresses in the 131.107.150.0/24 range. You do NOT need to provision the application gateway to complete this task.
To complete this task, sign in to the Azure portal.
Show Answer
Correct Answer: Azure portal → Web Application Firewall policies → Create (Application Gateway WAF policy, East US).
Add a Custom rule:
- Rule type: Match rule
- Match variable: RemoteAddr (Client IP)
- Operator: IPMatch
- Match values: 131.107.150.0/24
- Action: Block
Create the policy. If an application gateway already exists, associate the policy with it; do not create a new application gateway.
Explanation: The requirement is to create an Application Gateway WAF policy that blocks requests from the specified CIDR range using a custom IP match rule. Provisioning a new Application Gateway is not required.
Question 187
You have an Azure subscription that contains the following resources:
• A virtual network named Vnet1
• Two subnets named subnet1 and AzureFirewallSubnet
• A public Azure Firewall named FW1
• A route table named RT1 that is associated to Subnet1
• A rule routing of 0.0.0.0/0 to FW1 in RT1
After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machines were activated.
You need to ensure that the virtual machines can be activated.
What should you do?
A. On FW1, configure a DNAT rule for port 1688
B. Deploy a NAT gateway.
C. Add an internet route to RT1 for the Azure Key Management Service (KMS).
D. To Subnet1, associate a network security group (NSG) that allows outbound access to port 1688.
Show Answer
Correct Answer: C
Explanation: Windows Server activation in Azure uses Microsoft's Key Management Service (KMS) endpoint on TCP port 1688. Because the user-defined default route (0.0.0.0/0) sends all outbound traffic to Azure Firewall, the VMs' activation traffic is no longer taking the platform path. Adding a more specific route for the Azure KMS endpoint with next hop Internet allows activation traffic to bypass the forced-tunnel path while leaving other traffic routed through the firewall. A DNAT rule is for inbound traffic, a NAT Gateway does not change the routing issue, and an NSG rule alone does not help because routing still sends the traffic to the firewall.
Question 192
DRAG DROP
-
You have a DNS domain named contoso.com that is hosted by a third-party domain name registrar.
You have an Azure subscription.
You need to ensure that all DNS queries for the contoso.com domain are resolved by using Azure DNS.
What should you create in the registrar, and what should you create in Azure? To answer, drag the appropriate options to the correct targets. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Registrar: A delegation
Azure: A public DNS zone
Explanation: To host a public domain in Azure DNS, create a public DNS zone in Azure for the domain, then delegate the domain at the registrar by updating the NS delegation to Azure DNS name servers.
Question 194
You have an Azure subscription that contains four virtual machines. The virtual machines host an app named App1.
You deploy an Azure Standard Load Balancer named LB1 to load balance incoming HTTPS requests to App1.
You need to reduce how long it takes for LB1 to stop sending App1 traffic to failed servers. The solution must minimize administrative effort.
What should you modify?
A. the Backend pools settings
B. the Diagnostic settings
C. the Load-balancing rules
D. the Health probes settings
Show Answer
Correct Answer: D
Explanation: Modify the Health probes settings. Azure Standard Load Balancer determines backend availability using health probes. Reducing the probe interval (and associated failure threshold behavior) allows the load balancer to detect failed instances more quickly and stop sending them traffic, with minimal administrative effort. Backend pools, diagnostics, and load-balancing rules do not control failure detection timing.
Question 195
You have an Azure subscription that contains the resources shown in the following table.
Subnet1 contains three virtual machines that host an app named App1. App1 is accessed by using the SFTP protocol.
From NSG1, you configure an inbound security rule named Rule2 that allows inbound SFTP connections to ASG1.
You need to ensure that the inbound SFTP connections are managed by using ASG1. The solution must minimize administrative effort.
What should you do?
A. From NSG1, modify the priority of Rule2.
B. From each virtual machine, associate the network interface to ASG1.
C. From Subnet1, create a subnet delegation.
D. From ASG1, modify the role assignments.
Show Answer
Correct Answer: B
Explanation: Application Security Groups (ASGs) are applied by associating virtual machine network interfaces with the ASG. An NSG rule that targets ASG1 only affects NICs that are members of ASG1. Associating each VM's network interface with ASG1 enables Rule2 to manage inbound SFTP traffic with minimal administrative effort. Changing rule priority, creating a subnet delegation, or modifying role assignments does not make the VMs members of the ASG.
Question 196
You are planning the IP addressing for the subnets in Azure virtual networks.
Which type of resource requires IP addresses in the subnets?
A. storage account
B. internal load balancers
C. service endpoints
D. virtual network peering
Show Answer
Correct Answer: B
Explanation: Internal load balancers are assigned a frontend private IP address from the subnet, so they consume IP addresses within that subnet. Storage accounts, service endpoints, and virtual network peering do not consume subnet IP addresses.
$19
Get all 347 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.