Microsoft Designing and Implementing Microsoft Azure Networking Solutions - AZ-700 FREE EXAM DUMPS QUESTIONS & ANSWERS
You need to implement name resolution for the cloud.liwareinc.com. The solution must meet the networking requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/dns/private-dns-autoregistration
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-name-resolution-for-vms-and-role-instances
You have an Azure virtual network named Vnet1.
You need to ensure that the virtual machines in Vnet1 can access only the Azure SQL resources in the East US Azure region. The virtual machines must be prevented from accessing any Azure Storage resources.
Which two outbound network security group (NSG) rules should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point
You need to ensure that the virtual machines in Vnet1 can access only the Azure SQL resources in the East US Azure region. The virtual machines must be prevented from accessing any Azure Storage resources.
Which two outbound network security group (NSG) rules should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point
Correct Answer: A,D
Vote an answer
You have an on-premises network.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 is connected to an Azure Virtual WAN hub named Hub1.
You need to enable connectivity between the on-premises network and VNet1 by using Hub1.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 is connected to an Azure Virtual WAN hub named Hub1.
You need to enable connectivity between the on-premises network and VNet1 by using Hub1.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation:

You have the Azure environment shown In the Azure Environment exhibit. (Click the Azure Environment tab.) The settings for each subnet are shown in the following table.

The Firewalls and virtual networks settings for storage1 are configured as shown in the Storage1 exhibit.
(Click the Storage1 tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.


The Firewalls and virtual networks settings for storage1 are configured as shown in the Storage1 exhibit.
(Click the Storage1 tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

You have an Azure subscription that contains a user named User1 and the resources shown in the following table.

You need to ensure that User1 can associate Policy1 to FW1 by using Azure Firewall Manager. The solution must follow the principle of least privilege.
Which role should you assign to User1 for each resource group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You need to ensure that User1 can associate Policy1 to FW1 by using Azure Firewall Manager. The solution must follow the principle of least privilege.
Which role should you assign to User1 for each resource group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

You are planning the IP addressing for the subnets in Azure virtual networks. Which type of resource requires IP addresses in the subnets?
Correct Answer: C
Vote an answer
Task 10
You plan to deploy several virtual machines to subnet1-2.
You need to prevent all Azure hosts outside of subnetl-2 from connecting to TCP port 5585 on hosts on subnet1-2. The solution must minimize administrative effort.
You plan to deploy several virtual machines to subnet1-2.
You need to prevent all Azure hosts outside of subnetl-2 from connecting to TCP port 5585 on hosts on subnet1-2. The solution must minimize administrative effort.
Correct Answer:
See the Explanation below for step by step instructions.
Explanation:
To prevent all Azure hosts outside of subnet1-2 from connecting to TCP port 5585 on hosts within subnet1-2, you can use a Network Security Group (NSG). This solution is straightforward and minimizes administrative effort.
Step-by-Step Solution
Step 1: Create a Network Security Group (NSG)
Navigate to the Azure Portal.
Search for "Network security groups" and select it.
Click on "Create".
Enter the following details:
Subscription: Select your subscription.
Resource Group: Select an existing resource group or create a new one.
Name: Enter a name for the NSG (e.g., NSG-Subnet1-2).
Region: Select the region where your virtual network is located.
Click on "Review + create" and then "Create".
Step 2: Create an Inbound Security Rule
Navigate to the newly created NSG.
Select "Inbound security rules" from the left-hand menu.
Click on "Add" to create a new rule.
Enter the following details:
Source: Select Service Tag.
Source Service Tag: Select VirtualNetwork.
Source port ranges: Leave as *.
Destination: Select IP Addresses.
Destination IP addresses/CIDR ranges: Enter the IP range of subnet1-2 (e.g., 10.1.2.0/24).
Destination port ranges: Enter 5585.
Protocol: Select TCP.
Action: Select Deny.
Priority: Enter a priority value (e.g., 100).
Name: Enter a name for the rule (e.g., Deny-TCP-5585).
Click on "Add" to create the rule.
Step 3: Associate the NSG with Subnet1-2
Navigate to the virtual network that contains subnet1-2.
Select "Subnets" from the left-hand menu.
Select subnet1-2 from the list of subnets.
Click on "Network security group".
Select the NSG you created (NSG-Subnet1-2).
Click on "Save".
Explanation:
Network Security Group (NSG): NSGs are used to filter network traffic to and from Azure resources in an Azure virtual network. They contain security rules that allow or deny inbound and outbound traffic based on source and destination IP addresses, port, and protocol1.
Inbound Security Rule: By creating a rule that denies traffic on TCP port 5585 from any source outside of subnet1-2, you ensure that only hosts within subnet1-2 can connect to this port.
Association with Subnet: Associating the NSG with subnet1-2 ensures that the security rules are applied to all resources within this subnet.
By following these steps, you can effectively prevent all Azure hosts outside of subnet1-2 from connecting to TCP port 5585 on hosts within subnet1-2, while minimizing administrative effort.
Explanation:
To prevent all Azure hosts outside of subnet1-2 from connecting to TCP port 5585 on hosts within subnet1-2, you can use a Network Security Group (NSG). This solution is straightforward and minimizes administrative effort.
Step-by-Step Solution
Step 1: Create a Network Security Group (NSG)
Navigate to the Azure Portal.
Search for "Network security groups" and select it.
Click on "Create".
Enter the following details:
Subscription: Select your subscription.
Resource Group: Select an existing resource group or create a new one.
Name: Enter a name for the NSG (e.g., NSG-Subnet1-2).
Region: Select the region where your virtual network is located.
Click on "Review + create" and then "Create".
Step 2: Create an Inbound Security Rule
Navigate to the newly created NSG.
Select "Inbound security rules" from the left-hand menu.
Click on "Add" to create a new rule.
Enter the following details:
Source: Select Service Tag.
Source Service Tag: Select VirtualNetwork.
Source port ranges: Leave as *.
Destination: Select IP Addresses.
Destination IP addresses/CIDR ranges: Enter the IP range of subnet1-2 (e.g., 10.1.2.0/24).
Destination port ranges: Enter 5585.
Protocol: Select TCP.
Action: Select Deny.
Priority: Enter a priority value (e.g., 100).
Name: Enter a name for the rule (e.g., Deny-TCP-5585).
Click on "Add" to create the rule.
Step 3: Associate the NSG with Subnet1-2
Navigate to the virtual network that contains subnet1-2.
Select "Subnets" from the left-hand menu.
Select subnet1-2 from the list of subnets.
Click on "Network security group".
Select the NSG you created (NSG-Subnet1-2).
Click on "Save".
Explanation:
Network Security Group (NSG): NSGs are used to filter network traffic to and from Azure resources in an Azure virtual network. They contain security rules that allow or deny inbound and outbound traffic based on source and destination IP addresses, port, and protocol1.
Inbound Security Rule: By creating a rule that denies traffic on TCP port 5585 from any source outside of subnet1-2, you ensure that only hosts within subnet1-2 can connect to this port.
Association with Subnet: Associating the NSG with subnet1-2 ensures that the security rules are applied to all resources within this subnet.
By following these steps, you can effectively prevent all Azure hosts outside of subnet1-2 from connecting to TCP port 5585 on hosts within subnet1-2, while minimizing administrative effort.
You have an Azure subscription that contains virtual networks, network security groups (NSGs), and virtual machines. You need to perform the following actions:
* Identify unknown traffic between the resources.
* Check the network connectivity between the virtual machines.
What should you use to perform each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

* Identify unknown traffic between the resources.
* Check the network connectivity between the virtual machines.
What should you use to perform each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.
You configure the application gateway to direct traffic to the URL of the application gateway.
You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.
Solution: You disable the WAF rule that has a ruleld of 920300.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.
You configure the application gateway to direct traffic to the URL of the application gateway.
You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.
Solution: You disable the WAF rule that has a ruleld of 920300.
Does this meet the goal?
Correct Answer: B
Vote an answer
You have two Azure App Service instances that host the web apps shown the following table.

You deploy an Azure application gateway that has one public frontend IP address and two backend pools.
You need to publish all the web apps to the application gateway. Requests must be routed based on the HTTP host headers.
What is the minimum number of listeners and routing rules you should configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You deploy an Azure application gateway that has one public frontend IP address and two backend pools.
You need to publish all the web apps to the application gateway. Requests must be routed based on the HTTP host headers.
What is the minimum number of listeners and routing rules you should configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:
1, 2
Your on-premises network uses an IP address range of 10.1.0.0 to 10.1.255.255.
You plan to deploy a new Azure virtual network solution that will include the following elements:
* A virtual network named VNet1
* A Site-to-Site (S2S) VPN connection between VNet1 and the on-premises network
* GatewaySubnet in VNet1, which will be used as a route-based virtual network gateway You need to recommend which subnet masks to assign to VNet1 and GatewaySubnet. The solution must meet the following requirements:
* Maximize the number of available IP addresses on VNet1.
* Minimize the number of available IP addresses on GatewaySubnet
Which address spaces should you assign to VNet1 and GatewaySubnet? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to deploy a new Azure virtual network solution that will include the following elements:
* A virtual network named VNet1
* A Site-to-Site (S2S) VPN connection between VNet1 and the on-premises network
* GatewaySubnet in VNet1, which will be used as a route-based virtual network gateway You need to recommend which subnet masks to assign to VNet1 and GatewaySubnet. The solution must meet the following requirements:
* Maximize the number of available IP addresses on VNet1.
* Minimize the number of available IP addresses on GatewaySubnet
Which address spaces should you assign to VNet1 and GatewaySubnet? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
