πŸ”

AZ-700 β€” questions

Page 7 of 9 Β· 172 total questions.

Topic 4 Β· Question 271

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Front Door Premium profile named AFD1 and an Azure Web Application Firewall (WAF) policy named WAF1. AFD1 is associated with WAF1. You need to configure a rate limit for incoming requests to AFD1. Solution: You configure a managed rule for WAF1. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 272

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Front Door Premium profile named AFD1 and an Azure Web Application Firewall (WAF) policy named WAF1. AFD1 is associated with WAF1. You need to configure a rate limit for incoming requests to AFD1. Solution: You modify the policy settings of WAF1. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 273

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Front Door Premium profile named AFD1 and an Azure Web Application Firewall (WAF) policy named WAF1. AFD1 is associated with WAF1. You need to configure a rate limit for incoming requests to AFD1. Solution: You configure a custom rule for WAF1. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 4 Β· Question 274

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Front Door Premium profile named AFD1 and an Azure Web Application Firewall (WAF) policy named WAF1. AFD1 is associated with WAF1. You need to configure a rate limit for incoming requests to AFD1. Solution: You add a rule to the rule set of AFD1. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 280

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1. Hub1 has a security status of Unsecured. You need to ensure that the security status of Hub1 is marked as Secured. Solution: You implement an Azure Front Door profile. Does this meet the requirement?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 281

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1. Hub1 has a security status of Unsecured. You need to ensure that the security status of Hub1 is marked as Secured. Solution: You implement Azure Firewall. Does this meet the requirement?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 4 Β· Question 282

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1. Hub1 has a security status of Unsecured. You need to ensure that the security status of Hub1 is marked as Secured. Solution: You implement Azure NAT Gateway. Does this meet the requirement?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 283

You have an Azure subscription. You plan to deploy Azure Firewall Premium, enable all the Premium features, and configure both network and application rules. Which type of rule will the firewall process first?

  • Anetwork
  • Bapplication
  • Cthreat intelligence (correct answer)
  • Dinfrastructure
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: threat intelligence.

Topic 4 Β· Question 284

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1. Hub1 has a security status of Unsecured. You need to ensure that the security status of Hub1 is marked as Secured. Solution: You implement Azure Web Application Firewall (WAF). Does this meet the requirement?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 285

You have an Azure subscription that contains an Azure App Service web app named WebApp1 and an Azure Front Door profile named FDProfile1. FDProfile1 forwards requests addressed to https://www.contoso.com to WebApp1. You need to ensure that only requests addressed to https://www.contoso.com/users/* are forwarded to WebApp1. What should you modify in FDProfile1?

  • Athe routes (correct answer)
  • Bthe origin group
  • Cthe endpoint
  • Dthe domain
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: the routes.

Topic 4 Β· Question 287

You purchase an Azure subscription. You plan to deploy resources shown in the following table to the subscription. You need to create a NSG1 rule named Rule1 to meet the following requirements: β€’ Enable the search servers of App1 to establish outbound HTTP connections to internet services. β€’ Minimize administrative effort when new search servers are deployed. β€’ Use the principle of least privilege. What should you select as the source for Rule1?

Exhibit 1 for question 287
  • AApplication security group (correct answer)
  • BIP Addresses
  • CAny
  • DVirtualNetwork
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Application security group.

Topic 4 Β· Question 288

You have an Azure subscription that contains a virtual machine named VM1 and a network security group (NSG) named NSG1. NSG1 has the default rules configured. VM1 runs Windows Server 2022 and contains a single NIC named NIC1. NIC1 is associated with NSG1. You need to prevent access to the Azure Instance Metadata Service (IMDS) REST API on VM1. The solution must minimize administrative effort. What should you add to NSG1?

  • Aan outbound rule that blocks traffic to an IP address.
  • Ban inbound rule that blocks traffic to an IP address.
  • Can inbound and outbound rule that blocks traffic to an application security group.
  • Dan outbound rule that blocks traffic to a service tag. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: an outbound rule that blocks traffic to a service tag.

Topic 4 Β· Question 290

You have an Azure subscription that contains the resources shown in the following table. NSG1 is associated to the NIC of VM1 and contains the rules shown in the following table. You collect NSG flow logs for five minutes for the following activities: β€’ Two RDP sessions from VM1 to VM2, each initiated from a different TCP port β€’ Three SSH sessions from VM2 to VM1, each initiated from a different TCP port You analyze the logs by using Traffic Analytics in Azure Network Watcher. How many aggregated flow entries will Traffic Analytics identify?

Exhibit 1 for question 290Exhibit 2 for question 290
  • A1
  • B2
  • C5 (correct answer)
  • D10
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: 5.

Topic 4 Β· Question 293

You have an Azure subscription that contains an Azure Front Door named FD1. FD1 is configured as shown in the following exhibit. You need to enable Azure Private Link for FD1. What should you do first?

Exhibit 1 for question 293
  • AAdd an endpoint.
  • BCreate a custom route.
  • CCreate an origin group.
  • DChange Pricing Tier to Azure Front Door Premium. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Change Pricing Tier to Azure Front Door Premium.

Explanation

Azure Front Door provides global HTTP load balancing, caching, and WAF at the edge for low latency and failover.

Topic 4 Β· Question 294

You have an Azure subscription that contains an instance of Azure Firewall Standard named AzFW1. You plan to enable the following: β€’ TLS inspection β€’ Threat intelligence β€’ A network intrusion detection and prevention system (IDPS) What can you enable by using AzFW1?

  • ATLS inspection only
  • Bthreat intelligence only (correct answer)
  • CTLS inspection and the IDPS only
  • Dthreat intelligence and the IDPS only
  • ETLS inspection, threat intelligence, and the IDPS
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: threat intelligence only.

Topic 4 Β· Question 296

You have an Azure subscription that contains a resource group named RG1 and a virtual network named VNet1. You need to deploy Azure Firewall to RG1. The solution must minimize administrative effort. What should you do first?

  • ACreate a secured virtual hub named AzureFirewallHub.
  • BCreate a new virtual network named AzureFirewallNetwork.
  • CCreate a new resource group named AzurFirewellRescurceGroup.
  • DOn VNet1, create virtual subnet named AzureFirewallSubnet (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: On VNet1, create virtual subnet named AzureFirewallSubnet.

Topic 4 Β· Question 300 Β· Select all that apply

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an Azure Virtual Desktop host pool named Pool1. You need to implement Azure Firewall and TLS inspection for all the outbound traffic from Pool1. Which two resources should you configure? Each correct answer present part of the solution. NOTE: Each correct answer is worth one point.

  • Aan Azure Private DNS zone
  • Ba private endpoint
  • Can Azure key vault (correct answer)
  • Dan Azure NAT gateway
  • Ea Microsoft Entra enterprise app
  • Fa managed identity (correct answer)
Reveal answer & explanation
Correct answer: C, F

The correct answer is C, F. Option C: an Azure key vault Option F: a managed identity

Explanation

A Managed Identity lets Azure resources authenticate to services without storing credentials. Azure Key Vault securely stores and manages secrets, keys, and certificates with access policies.

Topic 4 Β· Question 301

You have an Azure virtual machine named VM1. You need to capture all the network traffic of VM1 by using Azure Network Watcher. To which locations can the capture be written?

  • Aa file path on VM1 only
  • BGeneral purpose v2 standard only
  • Ca Block blob premium account only
  • DGeneral purpose v2 standard and a file path on VM1 only (correct answer)
  • EGeneral purpose v2 standard and a Block blob premium account only
  • Fblob storage, a file path on VM1, and a Block blob premium account
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: General purpose v2 standard and a file path on VM1 only.

Topic 4 Β· Question 302

You have an Azure subscription that contains the following resources: β€’ A virtual network named Vnet1 β€’ Two subnets named subnet1 and AzureFirewallSubnet β€’ A public Azure Firewall named FW1 β€’ A route table named RT1 that is associated to Subnet1 β€’ A rule routing of 0.0.0.0/0 to FW1 in RT1 After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machine operating systems were activated. You need to ensure that the virtual machines can be activated. What should you do?

  • ADeploy a NAT gateway.
  • BOn FW1, create an outbound network rule that allows traffic to the Azure Key Management Service (KMS). (correct answer)
  • CTo Subnet1, associate a network security group (NSG) that allows outbound access to port 1688.
  • DDeploy an Azure Standard Load Balancer that has an outbound NAT rule.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: On FW1, create an outbound network rule that allows traffic to the Azure Key Management Service (KMS).

Topic 5 Β· Question 305

You have the Azure resources shown in the following table. You configure storage1 to provide access to the subnet in Vnet1 by using a service endpoint. You need to ensure that you can use the service endpoint to connect to the read-only endpoint of storage1 in the paired Azure region. What should you do first?

  • AFail over storage1 to the paired Azure region.
  • BConfigure the firewall settings for storage1.
  • CCreate a virtual network in the paired Azure region. (correct answer)
  • DCreate another service endpoint.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create a virtual network in the paired Azure region.

Showing questions 121–140 of 172 Β· Page 7 of 9