Microsoft AZ-720 Practice Test - Questions Answers, Page 12
List of questions
Related questions
You manage an Azure subscription that contains the following resources:
An on-premises environment is connected to VNet1 by using ERGW1.
An on-premises environment is connected to VNet1 by using ERGW1.
An administrator measures network latency for on-premises traffic that targets VM1 and VM2 by using the front-end IP address of the load balancer. The administrator enables ExpressRoute FastPath on ERGW1 and observes that the latency has not changed.
You need to resolve the issue that is preventing the network latency improvements offered by ExpressRoute FastPath from taking effect. What should you do?
A company has a pay-as-you-go subscription named Subl1.
The company has a virtual machine (VM) named VM1 in a subnet named Subnet1.
You create the following network security group (NSG) named NSG1 and associate it with Subnet1.
You observe that an application on VM1 is unable to send email to recipient outside the company You need to resolve the issue. What should you do?
A company has two subnet in a virtual network named VNe1m the subnet are named SubnetA and SubnetB. The company uses a site-to-site (S2) VPN in SubnetB to connect its on-premises environment to Azure. You deploy an Azure SQL Database named SQL1. You configure a service endpoint in SubnetA for Microsft.SqL
A company has a virtual machine (VM) named VM1 in a virtual network. The company also uses Azure Firewall Standard.
An administrator creates application rules to filter outbound traffic from VM1 and configure fully qualified domain names (FQDN) on the application rules.
The administrator discovers that outbound traffic from VM1 to the FQDNs are not being filtered by the firewall.
You need to resolve the issue with filtering.
What should you do first?
HOTSPOT
A company uses Azure Standard Load Balancer which is configured to export metrics to Azure Monitor.
You receive an email alert for a potential outbound port exhaustion issue from an Azure virtual machine. You add additional front-end IPs to the load balancer.
You need to monitor the load balancer.
How should you complete the configuration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
HOTSPOT
A company uses Azure Firewall. The firewall uses the following rules:
The company requires the following:
• Block outbound connections to Contoso.com on ports 80 and 443. You configure the NetRC2 firewall rule to block the connections. Users report that they can still access Contoso.com on port 80
• Allow outbound connections to Adatuin.com on ports 80 and 443. You configure the AppRC2 firewall rule to allow the connections. Users report that they can access the Adaturn com website by using the IP address but not by using the fully qualified domain name (FQDN).
You need to troubleshoot the rules that are causing the issues.
Which rules should you review? To answer, select the appropriate options in the answer area.
HOTSPOT
A company deploys just-in-time (JIT) virtual machine (VM) access.
A user reports that they are unable to request access to a JIT VM.
You need to determine the permission operations that are required for the user to request JIT access.
The solution should use the principle of least privilege.
Which permission operations are required? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A company uses Active Directory Federation Services {AD FS) to authenticate users to Azure AD.
Users report receiving a certificate warning after the company updates the AD FS certificate.
You need to ensure users can sign in to Azure AD. Which PowerShell cmdlet should you use?
HOTSPOT
A company uses Azure virtual machines (VMs) running Windows for hosting DNS. The company configures the Azure Log Analytics agent on the VMs.
The company is suspicious that some clients may have malware or that the DNS servers may be
compromised. You need to retrieve the following information for troubleshooting:
• Clients that try to resolve malicious domain names.
• Clients that exceed the threshold for the number of DNS lookup requests.
• Changes made to the DNS servers.
You add the DNS Analytics solution to the Azure Log Analytics workspace.
You need to retrieve the required DNS information.
Which query should you use? To answer, select the appropriate options in the answer area.
Question