Exams > Microsoft > AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
Page 3 out of 12 pages Questions 21-30 out of 116 questions
Question#21

You have an Azure subscription that contains an Azure App Service app. The app uses a URL of https://www.contoso.com.
You need to use a custom domain on Azure Front Door for www.contoso.com. The custom domain must use a certificate from an allowed certification authority
(CA).
What should you include in the solution?

  • A. an enterprise application in Azure Active Directory (Azure AD)
  • B. Active Directory Certificate Services (AD CS)
  • C. Azure Key Vault
  • D. Azure Application Gateway
Discover Answer Hide Answer

Answer: C
Reference:
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-custom-domain-https

Question#22

You have an Azure application gateway for a web app named App1. The application gateway allows end-to-end encryption.
You configure the listener for HTTPS by uploading an enterprise-signed certificate.
You need to ensure that the application gateway can provide end-to-end encryption for App1.
What should you do?

  • A. Increase the Unhealthy threshold setting in the custom probe.
  • B. Enable the SSL profile to the listener.
  • C. Set Listener type to Multi site.
  • D. Upload the public key certificate to the HTTP settings.
Discover Answer Hide Answer

Answer: D
Reference:
https://docs.microsoft.com/en-us/azure/application-gateway/end-to-end-ssl-portal

Question#23

HOTSPOT -
You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2.
You have the NAT gateway shown in the NATgateway1 exhibit.

You have the virtual machine shown in the VM1 exhibit.

Subnet1 is configured as shown in the Subnet1 exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Discover Answer Hide Answer

Answer:
Box 1: No -
VM1 is in Zone2 whereas the NAT Gateway is in Zone1. The VM would need to be in the same zone as the NAT Gateway to be able to use it. Therefore, VM1 cannot use the NAT gateway.

Box 2: Yes -
NATgateway1 is configured in the settings for Subnet2.

Box 3: No -
The NAT gateway does not have a single public IP address, it has an IP prefix which means more than one IP address. The VMs the use the NAT Gateway can use different public IP addresses contained within the IP prefix.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-gateway-resource

Question#24

You have an Azure application gateway named AppGW1 that balances requests to a web app named App1.
You need to modify the server variables in the response header of App1.
What should you configure on AppGW1?

  • A. HTTP settings
  • B. rewrites
  • C. rules
  • D. listeners
Discover Answer Hide Answer

Answer: B
Reference:
https://docs.microsoft.com/en-us/azure/application-gateway/rewrite-http-headers-url

Question#25

You have an Azure Virtual Desktop deployment that has 500 session hosts.
All outbound traffic to the internet uses a NAT gateway.
During peak business hours, some users report that they cannot access internet resources. In Azure Monitor, you discover many failed SNAT connections.
You need to increase the available SNAT connections.
What should you do?

  • A. Bind the NAT gateway to another subnet.
  • B. Add a public IP address.
  • C. Deploy Azure Standard Load Balancer that has outbound rules.
Discover Answer Hide Answer

Answer: B
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/nat-gateway/nat-gateway-resource

Question#26

You have an Azure subscription that contains the public IPv4 addresses shown in the following table.

You plan to create a load balancer named LB1 that will have the following settings:
✑ Name: LB1
✑ Location: West US
✑ Type: Public
✑ SKU: Standard
Which public IPv4 addresses can be used by LB1?

  • A. IP1, IP3, IP4, and IP5 only
  • B. IP3 only
  • C. IP1 and IP3 only
  • D. IP2 only
  • E. IP1, IP2, IP3, IP4, and IP5
  • F. IP3 and IP5 only
Discover Answer Hide Answer

Answer: F
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-public-ip-address

Question#27

You have the Azure environment shown in the exhibit.

VM1 is a virtual machine that has an instance-level public IP address (ILPIP).
Basic Load Balancer uses a public IP address. VM1 and VM2 are in the backend pool.
NAT Gateway uses a public IP address named IP3 that is associated to SubnetA.
VNet1 has a virtual network gateway that has a public IP address named IP4.
When initiating outbound traffic to the internet from VM1, which public address is used?

  • A. IP1
  • B. IP2
  • C. IP3
  • D. IP4
Discover Answer Hide Answer

Answer: A

Question#28

You are configuring two network virtual appliances (NVAs) in an Azure virtual network. The NVAs will be used to inspect all the traffic within the virtual network.
You need to provide high availability for the NVAs. The solution must minimize administrative effort.
What should you include in the solution?

  • A. Azure Standard Load Balancer
  • B. Azure Application Gateway
  • C. Azure Traffic Manager
  • D. Azure Front Door
Discover Answer Hide Answer

Answer: A
Reference:
https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/nva-ha?tabs=cli

Question#29

You have five virtual machines that run Windows Server. Each virtual machine hosts a different web app.
You plan to use an Azure application gateway to provide access to each web app by using a hostname of www.contoso.com and a different URL path for each web app, for example: https://www.contoso.com/app1.
You need to control the flow of traffic based on the URL path.
What should you configure?

  • A. HTTP settings
  • B. listeners
  • C. rules
  • D. rewrites
Discover Answer Hide Answer

Answer: C
Reference:
https://docs.microsoft.com/en-us/azure/application-gateway/url-route-overview

Question#30

You plan to publish a website that will use an FQDN of www.contoso.com. The website will be hosted by using the Azure App Service apps shown in the following table.

You plan to use Azure Traffic Manager to manage the routing of traffic for www.contoso.com between AS1 and AS2.
You create a Traffic Manager profile named TMprofile1. TMprofile1 uses the weighted traffic-routing method.
You need to ensure that Traffic Manager routes traffic for www.contoso.com.
Which DNS record should you create?

  • A. two A records that map www.contoso.com to 131.107.100.1 and 131.107.200.1
  • B. a CNAME record that maps www.contoso.com to TMprofile1.azurefd.net
  • C. a CNAME record that maps www.contoso.com to TMprofile1.trafficmanager.net
  • D. a TXT record that contains a string of as1.contoso.com and as2.contoso.com in the details
Discover Answer Hide Answer

Answer: C
Reference:
https://docs.microsoft.com/en-us/azure/traffic-manager/quickstart-create-traffic-manager-profile https://docs.microsoft.com/en-us/azure/app-service/configure-domain-traffic-manager

chevron rightPrevious Nextchevron right