Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Microsoft AZ-700 - Designing and Implementing Microsoft Azure Networking Solutions

Page: 3 / 6
Total 312 questions

Task 10

You plan to deploy several virtual machines to subnet1-2.

You need to prevent all Azure hosts outside of subnetl-2 from connecting to TCP port 5585 on hosts on subnet1-2. The solution must minimize administrative effort.

You have an Azure virtual machine named VM1.

You need to capture all the network traffic of VM1 by using Azure Network Watcher. To which locations can the capture be written?

A.

a file system path on VM1 only

B.

General purpose v2 standard storage account only

C.

a Block blob premium storage account only

D.

General purpose v2 path on VM1 only

E.

General purpose v2 standard storage account and a Block blob premium account only

You have an Azure subscription that contains an Azure Front Door named FD1.

You plan to deploy an app named App1 by using Azure App Service. Users will access App1 by using FD1.

You need to provide FD1 with access to Appl. The solution must meet the following requirements:

• Ensure that users can only access App1 by using FD1.

• Ensure that users cannot access App1 directly from the internet.

What should you create for App1?

A.

a subnet delegation

B.

a service endpoint

C.

an access restriction

D.

a private endpoint

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.

Task 11

You need to ensure that only hosts on VNET1 can access the slcnage42150372 storage account. The solution must ensure that access occurs over the Azure backbone network.

You have an Azure subscription that contains the resources shown in the following table.

You need to control access to storage1 by using NSG1 What should you configure first?

A.

the Azure Private Link service

B.

an application security group

C.

a private endpoint network policy

D.

a service endpoint

Task 1

You plan to deploy a firewall to subnetl-2. The firewall will have an IP address of 10.1.2.4.

You need to ensure that traffic from subnetl-1 to the IP address range of 192.168.10.0/24 is routed through the firewall that will be deployed to subnetl-2. The solution must be achieved without using dynamic routing protocols.

You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements.

What should you include in the solution?

A.

a service endpoint

B.

Azure Front Door

C.

a private endpoint

D.

Azure Traffic Manager

You need to prepare Vnet1 for the deployment of an ExpressRoute gateway. The solution must meet the hybrid connectivity requirements and the business requirements.

Which three actions should you perform in sequence for Vnet1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to provide access to storage2. The solution must meet the PaaS networking requirements and the business requirements.

Which connectivity method should you use?

A.

a service endpoint

B.

a private endpoint

C.

Azure Firewall

D.

Azure Front Door