ExamGecko
Home Home / Microsoft / AZ-700

Microsoft AZ-700 Practice Test - Questions Answers, Page 5

Question list
Search
Search

List of questions

Search

Related questions











You plan to publish a website that will use an FQDN of www.contoso.com. The website will be hosted by using the Azure App Service apps shown in the following table.

You plan to use Azure Traffic Manager to manage the routing of traffic for www.contoso.com between AS1 and AS2. You need to ensure that Traffic Manager routes traffic for www.contoso.com.

Which DNS record should you create?

A.
two A records that map www.contoso.com to 131.107.100.1 and 131.107.200.1
A.
two A records that map www.contoso.com to 131.107.100.1 and 131.107.200.1
Answers
B.
a CNAME record that maps www.contoso.com to TMprofile1.azurefd.net
B.
a CNAME record that maps www.contoso.com to TMprofile1.azurefd.net
Answers
C.
a CNAME record that maps www.contoso.com to TMprofile1.trafficmanager.net
C.
a CNAME record that maps www.contoso.com to TMprofile1.trafficmanager.net
Answers
D.
a TXT record that contains a string of as1.contoso.com and as2.contoso.com in the details
D.
a TXT record that contains a string of as1.contoso.com and as2.contoso.com in the details
Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/traffic-manager/quickstart-create-traffic-manager-profile

https://docs.microsoft.com/en-us/azure/app-service/configure-domain-traffic-manager

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.

You configure the application gateway to direct traffic to the URL of the application gateway.

You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and discover the following error.

You need to ensure that the URL is accessible through the application gateway.

Solution: You create a WAF policy exclusion for request headers that contain 137.135.10.24.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

You have a website that uses an FQDN of www.contoso.com. The DNS record for www. contoso.com resolves to an onpremises web server. You plan to migrate the website to an Azure web app named Web1. The website on Web1 will be published by using an Azure Front Door instance named ContosoFD1. You build the website on Web1.

You plan to configure ContosoFD1 to publish the website for testing.

When you attempt to configure a custom domain for www.contoso.com on ContosoFD1, you receive the error message shown in the exhibit. (Click the Exhibit tab.) You need to test the website and ContosoFD1 without affecting user access to the on-premises web server.

Which record should you create in the contoso.com DNS domain?

A.
a CNAME record that maps afdverify.www.contoso.com to ContosoFD1.azurefd.net
A.
a CNAME record that maps afdverify.www.contoso.com to ContosoFD1.azurefd.net
Answers
B.
a CNAME record that maps www.contoso.com to ContosoFD1.azurefd.net
B.
a CNAME record that maps www.contoso.com to ContosoFD1.azurefd.net
Answers
C.
a CNAME record that maps afdverify.www.contoso.com to afdverify.ContosoFD1.azurefd.net
C.
a CNAME record that maps afdverify.www.contoso.com to afdverify.ContosoFD1.azurefd.net
Answers
D.
a CNAME record that maps www.contoso.com to Web1.contoso.com
D.
a CNAME record that maps www.contoso.com to Web1.contoso.com
Answers
Suggested answer: C

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/frontdoor/front-door-custom-domain#map-the-temporary-afdverifysubdomain

You have the Azure load balancer shown in the Load Balancer exhibit.

LB2 has the backend pools shown in the Backend Pools exhibit.

You need to ensure that LB2 distributes traffic to all the members of VMSS1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.
Add a network interface to VMSS1.
A.
Add a network interface to VMSS1.
Answers
B.
Add a load balancing rule.
B.
Add a load balancing rule.
Answers
C.
Configure a health probe.
C.
Configure a health probe.
Answers
D.
Add a public IP address to each member of VMSS1.
D.
Add a public IP address to each member of VMSS1.
Answers
Suggested answer: B, C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/load-balancer/quickstart-load-balancer-standard-public-portal?tabs=option-1-createload-balancer-standard

You have an Azure virtual network that contains the subnets shown in the following table.

You deploy an Azure firewall to AzureFirewallSubnet. You route all traffic from Subnet2 through the firewall. You need to ensure that all the hosts on Subnet2 can access an external site located at https://*.contoso.com. What should you do?

A.
In a firewall policy, create a DNAT rule.
A.
In a firewall policy, create a DNAT rule.
Answers
B.
Create a network security group (NSG) and associate the NSG to Subnet2.
B.
Create a network security group (NSG) and associate the NSG to Subnet2.
Answers
C.
In a firewall policy, create a network rule.
C.
In a firewall policy, create a network rule.
Answers
D.
In a firewall policy, create an application rule.
D.
In a firewall policy, create an application rule.
Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal

You have an Azure Web Application Firewall (WAF) policy in prevention mode that is associated to an Azure Front Door instance. You need to configure the policy to meet the following requirements:

Log all connections from Australia.

Deny all connections from New Zealand.

Deny all further connections from a network of 131.107.100.0/24 if there are more than 100 connections during one minute. What is the minimum number of objects you should create?

A.
three custom rules that each has one condition
A.
three custom rules that each has one condition
Answers
B.
one custom rule that has three conditions
B.
one custom rule that has three conditions
Answers
C.
one custom rule that has one condition
C.
one custom rule that has one condition
Answers
D.
one rule that has two conditions and another rule that has one condition
D.
one rule that has two conditions and another rule that has one condition
Answers
Suggested answer: A

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/web-application-firewall/afds/afds-overview

You have an Azure subscription that contains multiple virtual machines in the West US Azure region. You need to use Traffic Analytics.

Which two resources should you create? Each correct answer presents part of the solution. (Choose two.) NOTE: Each correct answer selection is worth one point.

A.
an Azure Monitor workbook
A.
an Azure Monitor workbook
Answers
B.
a Log Analytics workspace
B.
a Log Analytics workspace
Answers
C.
a storage account
C.
a storage account
Answers
D.
an Azure Sentinel workspace
D.
an Azure Sentinel workspace
Answers
E.
an Azure Monitor data collection rule
E.
an Azure Monitor data collection rule
Answers
Suggested answer: B, C

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics

You have a hybrid environment that uses ExpressRoute to connect an on-premises network and Azure.

You need to log the uptime and the latency of the connection periodically by using an Azure virtual machine and an onpremises virtual machine. What should you use?

A.
Azure Monitor
A.
Azure Monitor
Answers
B.
IP flow verify
B.
IP flow verify
Answers
C.
Connection Monitor
C.
Connection Monitor
Answers
D.
Azure Internet Analyzer
D.
Azure Internet Analyzer
Answers
Suggested answer: C

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/network-watcher/connection-monitor

You have an Azure subscription that contains the following resources:

A virtual network named Vnet1

Two subnets named subnet1 and AzureFirewallSubnet A public Azure Firewall named FW1 A route table named RT1 that is associated to Subnet1 A rule routing of 0.0.0.0/0 to FW1 in RT1 After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machines were activated.

You need to ensure that the virtual machines can be activated.

What should you do?

A.
Deploy an application security croup mat allows outbound traffic to 1688
A.
Deploy an application security croup mat allows outbound traffic to 1688
Answers
B.
Deploy an Azure Standard Load Balancer that has an outbound NAT rule
B.
Deploy an Azure Standard Load Balancer that has an outbound NAT rule
Answers
C.
On fW1.configure a DNAT rule for port 1688.
C.
On fW1.configure a DNAT rule for port 1688.
Answers
D.
Add an internet route to RI1 for the Azure Key Management Service (KMS).
D.
Add an internet route to RI1 for the Azure Key Management Service (KMS).
Answers
Suggested answer: D

Explanation:

Reference: https://ryanmangansitblog.com/2020/05/11/firewall-considerations-windows-virtual-desktop-wvd/

You have an Azure virtual network that contains a subnet named Subnet1. Subnet1 is associated to a network security group (NSG) named NSG1. NSG1 blocks all outbound traffic that is not allowed explicitly. Subnet1 contains virtual machines that must communicate with the Azure Cosmos DB service.

You need to create an outbound security rule in NSG1 to enable the virtual machines to connect to Azure Cosmos DB. What should you include in the solution?

A.
a service tag
A.
a service tag
Answers
B.
a service endpoint policy
B.
a service endpoint policy
Answers
C.
a subnet delegation
C.
a subnet delegation
Answers
D.
an application security group
D.
an application security group
Answers
Suggested answer: A

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/virtual-network/service-tags-overview https://docs.microsoft.com/enus/azure/virtual-network/virtual-network-service-endpoint-policies-portal

Total 236 questions
Go to page: of 24