Current AZ-700 Exam Dumps [2025] Complete Microsoft Exam Smoothly [Q37-Q59]

Share

Current AZ-700  Exam Dumps [2025] Complete Microsoft Exam Smoothly

AZ-700 Premium PDF & Test Engine Files with 398 Questions & Answers


Microsoft AZ-700 exam is intended for IT professionals who have a deep understanding of Azure networking technologies and services, including virtual networks, VPNs, load balancers, and network security groups. Candidates for this certification should also have experience working with Azure services such as Azure Active Directory, Azure DNS, and Azure Traffic Manager. AZ-700 exam is typically taken by network architects, network engineers, and IT professionals who are responsible for designing and implementing Azure networking solutions for their organizations.


To cater to the growing need for expertise in Azure networking solutions, Microsoft has introduced the AZ-700 exam: Designing and Implementing Microsoft Azure Networking Solutions. AZ-700 exam is aimed at IT professionals who are well-versed in Azure networking solutions and are looking to enhance their skills and knowledge. AZ-700 exam is also ideal for network engineers, architects, and administrators who want to showcase their expertise in designing and implementing Azure networking solutions.

 

NEW QUESTION # 37
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso recently purchased an Azure subscription and is performing its first pilot project in Azure.
Existing Environment:
Azure Network Infrastructure
Contoso has an Azure Active Directory (Azure AD) tenant named contoso.com. The Azure subscription contains the virtual networks shown in the following table.

Vnet1 contains a virtual network gateway named GW1.
Azure Virtual Machines
The Azure subscription contains virtual machines that run Windows Server 2019 as shown in the following table.

The NSGs are associated to the network interfaces on the virtual machines. Each NSG has one custom security rule that allows RDP connections from the internet. The firewall on each virtual machine allows ICMP traffic.
An application security group named ASG1 is associated to the network interface of VM1.
Azure Network Infrastructure Diagram

Azure Private DNS Zones
The Azure subscription contains the Azure private DNS zones shown in the following table.

Zone1.contoso.com has the virtual network links shown in the following table.

Other Azure Resources
The Azure subscription contains additional resources as shown in the following table.

Requirements:
Virtual Network Requirements
Contoso has the following virtual networks requirements:
- Create a virtual network named Vnet6 in West US that will contain the following resources and configurations:
Two container groups that connect to Vnet6
Three virtual machines that connect to Vnet6
Allow VPN connections to be established to Vnet6
Allow the resources in Vnet6 to access KeyVault1, DB1, and Vnet1 over
the Microsoft backbone network
- The virtual machines in Vnet4 and Vnet5 must be able to communicate
over the Microsoft backbone network.
- A virtual machine named VM-Analyze will be deployed to Subnet1. VM-
Analyze must inspect the outbound network traffic from Subnet2 to the
internet.
Network Security Requirements
Contoso has the following network security requirements:
- Configure Azure Active Directory (Azure AD) authentication for Point- to-Site (P2S) VPN users.
- Enable NSG flow logs for NSG3 and NSG4.
- Create an NSG named NSG10 that will be associated to Vnet1/Subnet1
and will have the custom inbound security rules shown in the following
table.

- Create an NSG named NSG11 that will be associated to Vnet1/Subnet2
and will have the custom outbound security rules shown in the following table.

Hotspot Question
You need to restrict traffic from VMScaleSet1 to VMScaleSet2. The solution must meet the virtual networking requirements.
What is the minimum number of custom NSG rules and NSG assignments required? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Two custom rules
With the NSG attached to VMScaleSet2, you would need to create a custom rule blocking all traffic from VMScaleSet1. Then you would need to create another custom rule with a higher priority than the first rule that allows traffic on port 443.
The default rules in the NSG will allow all other traffic to VMScaleSet2.
Box 2: One NSG
The minimum requirement is one NSG. You could attach the NSG to VMScaleSet1 and restrict outbound traffic, or you could attach the NSG to VMScaleSet2 and restrict inbound traffic. Either way you would need two custom NSG rules.


NEW QUESTION # 38
You have an Azure firewall shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 39
Hotspot Question
You have an Azure subscription that contains the resources shown in the following table.

You create a service endpoint policy as shown in the Policy exhibit. (Click the Policy tab.)

You configure the Service Endpoints settings for Subnet3 as shown in the Subnets exhibit. (Click the Subnets tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 40
You have an Azure Front Door instance that provides access to a web app. The web app uses a hostname of www.contoso.com.
You have the routing rules shown in the following table.

Which rule will apply to each incoming request? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point

Answer:

Explanation:

Explanation
Table Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-route-matching


NEW QUESTION # 41
You have the Azure environment shown in the exhibit.

You have virtual network peering between Vnet1 and Vnet2. You have virtual network peering between Vnet4 and Vnet5. The virtual network peering is configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 42
You decide to protect your Azure Virtual Network resources using Azure Firewall. But there are a number of different possible issues with the Firewall.
In case of the issue "Threat intelligence alerts may get masked", how can you mitigate the issue?
(Choose two)

  • A. use https as the port: protocol value
  • B. Create outbound filtering for 80/443 using application rules.
  • C. Use authenticated SMTP relay services
  • D. Use only IPv4 addresses.
  • E. change the threat intelligence mode to Alert and Deny.

Answer: B,E

Explanation:
The mitigation strategy for the issue "Threat intelligence alerts may get masked" is: Create outbound filtering for 80/443 through application rules or modify the threat intelligence mode to Alert and Deny.
Option A is incorrect. Use https as the port: protocol value is the mitigation strategy for the issue
"FQDN tags require a protocol: port to be set".
Option B is correct. The given issue can be mitigated by creating outbound filtering for 80/443 using application rules.
Option C is correct. The given issue can be mitigated by changing the threat intelligence mode to Alert and Deny.
Option D is incorrect. Using authenticated SMTP relay services is not the right mitigation strategy.
Option E is incorrect. Using only IPv4 addresses is the mitigation strategy for the issue "IPv6 not currently supported".
Reference:
https://docs.microsoft.com/en-us/azure/firewall/overview?WT.mc_id=modinfra-33046-thmaure


NEW QUESTION # 43
You have an Azure subscription that contains the resources shown in the following table.

The virtual network topology is shown in the following exhibit.

Firewall1 is configured as shown in following exhibit.

FirewallPolicy1 contains the following rules:
* Allow outbound traffic from Vnet1 and Vnet2 to the internet.
* Allow any traffic between Vnet1 and Vnet2.
No custom private endpoints. service endpoints. routing tables, or network security groups (NSGs) were created. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 44
Task 5
You need to archive all the metrics of VNET1 to an existing storage account.

Answer:

Explanation:
See the Explanation below for step by step instructions.
Explanation:
To archive all the metrics of VNET1 to an existing storage account, you can use Azure Monitor's diagnostic settings. Here's how you can do it:
Step-by-Step Solution
Step 1: Navigate to VNET1 in the Azure Portal
* Open the Azure Portal.
* Search for "Virtual networks" and select VNET1 from the list.
Step 2: Configure Diagnostic Settings
* In the VNET1 blade, select "Diagnostic settings" under the "Monitoring" section.
* Click on "Add diagnostic setting".
Step 3: Set Up the Diagnostic Setting
* Enter a name for the diagnostic setting (e.g., VNET1-Metrics-Archive).
* Select the metrics you want to archive. You can choose from various metrics like TotalBytesReceived, TotalBytesSent, etc.
* Under "Destination details", select "Archive to a storage account".
* Choose the existing storage account where you want to archive the metrics.
* Configure the retention period if needed.
Step 4: Save the Configuration
* Review your settings to ensure everything is correct.
* Click on "Save" to apply the diagnostic setting.
Explanation:
* Diagnostic Settings: These allow you to collect and route metrics and logs from your Azure resources to various destinations, including storage accounts, Log Analytics workspaces, and Event Hubs.
* Metrics: Metrics provide numerical data about the performance and health of your resources. Archiving these metrics helps in long-term analysis and compliance.
* Storage Account: Using an existing storage account ensures that the metrics are stored securely and can be accessed for future analysis.
By following these steps, you can ensure that all the metrics of VNET1 are archived to your existing storage account, enabling you to monitor and analyze the performance and health of your virtual network over time.


NEW QUESTION # 45
Your company has 10 instances of a web service. Each instance is hosted in a different Azure region and is accessible through a public endpoint.
The development department at the company is creating an application named App1. Every 10 minutes. App1 will use a list of end points and connect to the first available endpoint.
You plan to use Azure Traffic Manager to maintain the list of endpoints.
You need to configure a Traffic Manager profile that will minimize the impact of DNS caching.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-routing-methods
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-endpoint-types


NEW QUESTION # 46
You have two Azure subscriptions named Subscnption1 and Subscription2. Subscription1 contains a virtual network named Vnet1. Vnet1 contains an application server. Subscription2 contains a virtual network named Vnet2.
You need to provide the virtual machines in Vnet2 with access to the application server in Vnet1 by using a private endpoint.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - In Subscription1, accept the private endpoint connection request.
2 - Enable virtual network peering between Vnet1 and Vnet2.
3 - Deploy an Azure Standard Load Balancer in fron of the application server.
4 - In Subscription1, create a private link service...


NEW QUESTION # 47
You are implementing the Virtual network requirements for Vnet6.
What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 48
You need to deploy Azure Virtual Network Manager. The solution must support the planned changes and meet the connectivity requirements.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:


NEW QUESTION # 49
You have the Azure subscriptions shown in the following table.

Each virtual network contains 20 internet-accessible resources that are assigned public IP addresses.
You need to implement Azure DDoS Network Protection to protect the resources. The solution must minimize costs.
What is the minimum number of DDoS Network Protection plans you should deploy?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 50
Hotspot Question
You have an Azure subscription that contains virtual networks, network security groups (NSGs), load balancer, virtual machines, and virtual network gateways.
You enable Azure Monitor Network Insights.
You need to perform the following actions:
- Review the NSG flow logs.
- Monitor resource utilization.
- Review the results of IP flow verify testing.
Which Azure Monitor Network Insights feature should you use for each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Traffic
Traffic Analytics within Network Insights can be used to monitor network traffic to and from clusters and identify potential data exfiltration. This feature, also part of Azure Monitor Network Insights, leverages NSG flow logs to provide a comprehensive view of traffic flow, helping you identify potential security risks and optimize network configurations.
Box 2: Topology
To monitor resource utilization in your Azure network, use Network Watcher's Topology and Traffic Analytics features in conjunction with Azure Monitor's Metrics and Logs capabilities Azure Monitor Network Insights:
Topology:
Provides a visual representation of your Azure virtual network and connected resources, helping you understand the relationships between them. You can drill down into specific resources, like VMs, to see their traffic and connectivity insights and access diagnostic tools.
Box 3: Diagnostic Toolkit
Diagnostic Toolkit provides access to all the diagnostic features available for troubleshooting the network. You can use this drop-down list to access features like packet capture, VPN troubleshoot, connection troubleshoot, next hop, and IP flow verify:
Reference:
https://learn.microsoft.com/en-us/azure/network-watcher/network-insights-overview


NEW QUESTION # 51
Hotspot Question
You have an Azure subscription. The subscription contains virtual machines that host websites as shown in the following table.

You have the Azure Traffic Manager profiles shown in the following table.

You have the endpoints shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: No
VM1, which is hosting site1.contoso.com, is located in East US. The VM1 endpoint status is degraded. Endpoint monitoring health checks are failing. The endpoint isn't included in DNS responses and doesn't receive traffic.
When an endpoint has a Degraded status, it's no longer returned in response to DNS queries.
Instead, an alternative endpoint is chosen and returned. The traffic- routing method configured in the profile determines how the alternative endpoint is chosen.
Priority. Endpoints form a prioritized list. The first available endpoint on the list is always returned.
If an endpoint status is Degraded, then the next available endpoint is returned.
The user will connect to site2.us.contoso.com instead.
Box 2: No
VM3, which is hosting site2.contoso.com, is located in in East US. The VM3 endpoint status is CheckingEndpoint. The endpoint is monitored, but the results of the first probe haven't been received yet. CheckingEndpoint is a temporary state that usually occurs immediately after adding or enabling an endpoint in the profile. An endpoint in this state is included in DNS responses and can receive traffic.
User will connect to site2.contoso.com, not to site2.uk.contoso.com
Box 3: No
VM3, which is hosting site2.contoso.com, is located in in East US. The VM1 endpoint status is CheckingEndpoint, which is OK (see above).
User will connect to site2.contoso.com, not to site2.japan.contoso.com
Reference:
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-monitoring


NEW QUESTION # 52
You have an Azure subscription that contains the resources shown in the following table.

VNet1 contains a subnet named Subnet.
You need to ensure that the resources connected to Subnet1 can access only storage1 and storage3. The solution must minimize administrative effort.
What should you configure?

  • A. Azure Private Link
  • B. a service endpoint policy
  • C. an application security group
  • D. a service tag

Answer: B

Explanation:
Service endpoint policies are allow policies, so apart from the specified resources, all other resources are restricted.
https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoint-policies- overview


NEW QUESTION # 53
You have the Azure environment shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 54
Your on-premises network contains a VPN device.
You have an Azure subscription that contains a virtual network and a virtual network gateway.
You need to create a Site-to-Site VPN connection that has a custom cryptographic policy.
How should you complete the PowerShell script? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 55
You
have an Azure application gateway named AGW1 that has a routing rule named Rule1. Rule 1 directs traffic for http://www.contoso.com to a backend poo l named Pool1. Pool1 targets an Azure virtual machine scale set named VMSS1.
You deploy another virtual machine scale set named VMSS2.
You
need to configure AGW1 to direct all traffic for http://www.adatum.com to VMSS2.
The solution must ensure that requests
to http://www.contoso.com continue to be directed to Pool1.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Add an HTTP setting.
  • B. Add a listener.
  • C. Add a backend pool.
  • D. Add a rule.
  • E. Modify an HTTP setting.

Answer: B,C,D

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/application-gateway/configuration-overview


NEW QUESTION # 56
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains the resources shown in the following table.

You need to publish App1 by using AG1 and a URL of https://app1.contoso.com. The solution must meet the following requirements:
* TLS connections must terminate on AG1.
* Minimize the number of targets in the backend pool of AG1.
* Minimize the number of deployed copies of the SSL certificate of App1.
How many locations should you import to the certificate, and how many targets should you add to the backend pool of AG1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 57
You have an Azure virtual network named Vnet1 that connects to an on-premises network.
You have an Azure Storage account named storageaccount1 that contains blob storage.
You need to configure a private endpoint for the blob storage. The solution must meet the following requirements:
Ensure that all on-premises users can access storageaccount1 through the private endpoint.
Prevent access to storageaccount1 from being interrupted.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Configure a private endpoint on storageaccount1 and disable public access to the account
2 - Deploy a virtual machine to a subnet in Vnet1
3 - Install the DNS server role and configure the forwarding of blob.core.windows.net to 168.63.129.16
4 - Configure on-premises DNS servers to forward blob.core.windows.net to the virtual machine Reference:
https://docs.microsoft.com/en-us/azure/storage/common/storage-private-endpoints


NEW QUESTION # 58
You need to recommend a configuration for the ExpressRoute connection from the Boston datacenter. The solution must meet the hybrid networking requirements and business requirements.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

For the first question, only ExpressRoute GW SKU Ultra Performance support FastPath feature.
For the second question, vnet1 will connect to ExpressRoute gw, once Vnet1 peers with Vnet2, the traffic from on-premise network will bypass GW and Vnet1, directly goes to Vnet2, while this feature is under public preview.
====Reference
ExpressRoute virtual network gateway is designed to exchange network routes and route network traffic.
FastPath is designed to improve the data path performance between your on-premises network and your virtual network. When enabled, FastPath sends network traffic directly to virtual machines in the virtual network, bypassing the gateway.
To configure FastPath, the virtual network gateway must be either:
Ultra Performance
ErGw3AZ
VNet Peering - FastPath will send traffic directly to any VM deployed in a virtual network peered to the one connected to ExpressRoute, bypassing the ExpressRoute virtual network gateway.
https://docs.microsoft.com/en-us/azure/expressroute/about-fastpath
Gateway SKU
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-about-virtual-network-gateways


NEW QUESTION # 59
......

AZ-700 Premium Files Practice Valid Exam Dumps Question: https://www.suretorrent.com/AZ-700-exam-guide-torrent.html

Get 100% Real AZ-700 Accurate & Verified Answers As Seen in the Real Exam!: https://drive.google.com/open?id=1BECcosACbFVsfUBUr3x3PKRbj8Emg1BC