Spring Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

AZ-700 Designing and Implementing Microsoft Azure Networking Solutions Questions and Answers

Questions 4

You have an on-premises datacenter named Site1 that contains a firewall named FW1. FW1 connects to the internet.

You have an Azure subscription that contains the resources shown in the following table.

AZ-700 Question 4

You plan to connect Site1 to Hub1 by using a site-to-site connection.

You need to configure the site-to-site connection to FW1.

What should you create in VWAN1?

Options:

A.

a VPN site

B.

a virtual network connection

C.

a network virtual appliance (NVA)

D.

a User VPN configuration

Buy Now
Questions 5

You have an Azure subscription that contains a virtual network named VNet1.

You need to deploy an instance of Azure Application Gateway v2 named AppGw1 to VNet1. AppGw1 will include one basic listener and two multi-site listeners. The listeners will be accessible only from VNet1.

What is the minimum number of IP addresses required for AppGw1? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

AZ-700 Question 5

Options:

Buy Now
Questions 6

You have an Azure subscription that contains a virtual network gateway named VNetGwy1. VNetGwy1 has a public IP address of 20.25.32.214.

You need to query the health probe of VNetGwy1,

How should you complete the URI? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 6

Options:

Buy Now
Questions 7

You have an Azure subscription that contains the resources shown in the following table.

AZ-700 Question 7

Users on HP1 connect to App1 by using a URL of https://app1 .comoso.com.

You need to ensure that the IDPS on FW1 can identify security threats in the connections from HP1 to Server1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Enable TLS inspection for FW1.

B.

import a server certificate to KV1.

C.

Enable threat intelligence for FW1.

D.

Add an application group to HP1.

E.

Add a secured virtual network to FW1.

Buy Now
Questions 8

You need to implement name resolution for the cloud.liwareinc.com. The solution must meet the networking requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 8

Options:

Buy Now
Questions 9

Task 1

You plan to deploy a firewall to subnetl-2. The firewall will have an IP address of 10.1.2.4.

You need to ensure that traffic from subnetl-1 to the IP address range of 192.168.10.0/24 is routed through the firewall that will be deployed to subnetl-2. The solution must be achieved without using dynamic routing protocols.

Options:

Buy Now
Questions 10

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.

Options:

Buy Now
Questions 11

You have an Azure subscription that contains multiple virtual machines in the West US Azure region.

You need to use Traffic Analytics.

Which two resources should you create? Each correct answer presents part of the solution. (Choose two.)

NOTE: Each correct answer selection is worth one point.

Options:

A.

an Azure Monitor workbook

B.

a Log Analytics workspace

C a storage account

C.

an Azure Sentinel workspace

D.

an Azure Monitor data collection rule

Buy Now
Questions 12

Task 3

You need to ensure that hosts on VNET1 and VNET2 can communicate. The solution must minimize latency between the virtual networks.

Options:

Buy Now
Questions 13

You have an Azure Web Application Firewall (WAF) policy in prevention mode that is associated to an Azure Front Door instance.

You need to configure the policy to meet the following requirements:

    Log all connections from Australia.

    Deny all connections from New Zealand.

    Deny all further connections from a network of 131.107.100.0/24 if there are more than 100 connections during one minute.

What is the minimum number of objects you should create?

Options:

A.

three custom rules that each has one condition

B.

one custom rule that has three conditions

C.

one custom rule that has one condition

D.

one rule that has two conditions and another rule that has one condition

Buy Now
Questions 14

Task 4

You need to ensure that the owner of VNET3 receives an alert if an administrative operation is performed on the virtual network.

Options:

Buy Now
Questions 15

Your company has an Azure subscription that contains a virtual network named VNet1 and an Azure VPN gateway named vGW1. The company has 50 users that have Windows 11 devices.

You need to ensure that the users can access the resources on VNet1. The solution must meet the following requirements:

• Ensure that the users can establish Point-to-Site (P2S) VPN connections to vGW1.

• Ensure that the users can authenticate by using only their Microsoft Entra credentials

Which type of tunnel should you configure, and which VPN client should you configure on the users' devices? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 15

Options:

Buy Now
Questions 16

You have an Azure subscription that contains 20 virtual machines and a virtual network named VNetl.

You plan to provide access to the virtual machines by using Azure Bastion.

You need to configure a subnet for Azure Bastion. The solution must minimize the number of IP addresses required for the subnet

How should you configure the subnet? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 16

Options:

Buy Now
Questions 17

N NO: 1

You need to configure the default route on Vnet2 and Vnet3. The solution must meet the virtual networking requirements.

What should you use to configure the default route?

Options:

A.

route filters

B.

BGP route exchange

C.

a user-defined route assigned to GatewaySubnet in Vnet1

D.

a user-defined route assigned to GatewaySubnet in Vnet2 and Vnet3

Buy Now
Questions 18

Task 11

You are preparing to connect your on-premises network to VNET4 by using a Site-to-Site VPN. The on-premises endpoint of the VPN will be created on a firewall named Firewall 1.

The on-premises network has the following configurations:

• Internal address range: 10.10.0.0/16.

• Firewall 1 internal IP address: 10.10.1.1.

• Firewall1 public IP address: 131.107.50.60.

BGP is NOT used.

You need to create the object that will provide the IP addressing configuration of the on-premises network to the Site-to-Site VPN. You do NOT need to create a virtual network gateway to complete this task.

Options:

Buy Now
Questions 19

You have two Azure subscriptions named Sub1 and Sub2. Sub1 contains a virtual machine named VM1.

You plan to make VM1 available to the resources in Sub2 by using Azure Private Link.

You need to ensure that the private link service can be configured to provide access to VM1.

What should you configure in Sub1 first?

Options:

A.

a service endpoint

B.

an Azure Private DNS zone

C.

a private endpoint

D.

an Azure load balancer

Buy Now
Questions 20

You have an Azure virtual network named Vnet1.

You need to ensure that the virtual machines in Vnet1 can access only the Azure SQL resources in the East US Azure region. The virtual machines must be prevented from accessing any Azure Storage resources.

Which two outbound network security group (NSG) rules should you create? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

a deny rule that has a source of Virtual Network service tag and a destination of Sql service tag

B.

a deny rule that has a source of IP address range of Vnet1 and destination of Storage service tag.

C.

a deny rule that has a source of VirtualNetwork service tag and a destination of 168.63.129.0/24 IP Addresses

D.

an allow rule that has a source of IP address range of Vnet1 and destination of Sql.EastUS service tag

Buy Now
Questions 21

You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements.

What should you include in the solution?

Options:

A.

a service endpoint

B.

Azure Front Door

C.

a private endpoint

D.

Azure Traffic Manager

Buy Now
Questions 22

You need to provide access to storage2. The solution must meet the PaaS networking requirements and the business requirements.

Which connectivity method should you use?

Options:

A.

a service endpoint

B.

a private endpoint

C.

Azure Firewall

D.

Azure Front Door

Buy Now
Questions 23

You need to restrict traffic from VMScaleSet1 to VMScaleSet2. The solution must meet the virtual networking requirements.

What is the minimum number of custom NSG rules and NSG assignments required? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Ite rule for the AZ-700 Question 23

Options:

Buy Now
Questions 24

You need to prepare Vnet1 for the deployment of an ExpressRoute gateway. The solution must meet the hybrid connectivity requirements and the business requirements.

Which three actions should you perform in sequence for Vnet1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-700 Question 24

Options:

Buy Now
Questions 25

You need to recommend a configuration for the ExpressRoute connection from the Boston datacenter. The solution must meet the hybrid networking requirements and business requirements.

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 25

Options:

Buy Now
Questions 26

You need to implement outbound connectivity for VMScaleSet1. The solution must meet the virtual networking requirements and the business requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-700 Question 26

Options:

Buy Now
Questions 27

You need to implement a P2S VPN for the users in the branch office. The solution must meet the hybrid networking requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 27

Options:

Buy Now
Questions 28

You need to connect Vnet2 and Vnet3. The solution must meet the virtual networking requirements and the business requirements.

Which two actions should you include in the solution? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

On the peerings from Vnet2 and Vnet3, select Use remote gateways.

B.

On the peering from Vnet1, select Allow forwarded traffic.

C.

On the peering from Vnet1, select Use remote gateways.

D.

On the peering from Vnet1, select Allow gateway transit.

E.

On the peerings from Vnet2 and Vnet3, select Allow gateway transit.

Buy Now
Questions 29

You have an Azure virtual network named Vnet1 that contains two subnets named Subnet1 and Subnet2. Both subnets contain virtual machines. You create a NAT gateway named NATgateway1 as shown in the following exhibit.

AZ-700 Question 29

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

AZ-700 Question 29

Options:

Buy Now
Questions 30

You create an ExpressRoute circuit named ERC1 that is enabled by your connectivity provider.

You need to ensure that the routes for Azure Backup and Azure Cosmos DB are advertised to the on-premises network via ECR1. The solution must minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 30

Options:

Buy Now
Questions 31

You have an Azure subscription that contains a virtual network named Vnet1. Vnet1 contains 20 subnets and 500 virtual machines. Each subnet contains a virtual machine that runs network monitoring software.

You have a network security group (NSG) named NSG1 associated to each subnet.

When a new subnet is created in Vnet1, an automated process creates an additional network monitoring virtual machine in the subnet and links the subnet to NSG1.

You need to create an inbound security rule in NS61 that will allow connections to the network monitoring virtual machines from an IP address of 131.107.1.15. The solution must meet the following requirements:

• Ensure that only the monitoring virtual machines receive a connection from 131.107.1.15.

• Minimize changes to NSG1 when a new subnet is created.

What should you use as the destination in the inbound security rule?

Options:

A.

a virtual network

B.

an IP address

C.

an application security group

D.

a service tag

Buy Now
Questions 32

You have an application named App1 that listens for incoming requests on a preconfigured group of 50 TCP ports and UDP ports.

You install App1 on 10 Azure virtual machines.

You need to implement load balancing for App1 across all the virtual machines. The solution must minimize the number of load balancing rules.

What should you include in the solution?

Options:

A.

Azure Standard Load Balancer that has Floating IP enabled

B.

Azure Application Gateway V2 that has multiple listeners

C.

Azure Application Gateway v2 that has multiple site hosting enabled

D.

Azure Standard Load Balancer that has high availability (HA) ports enabled

Buy Now
Questions 33

You have an on-premises network and an Azure virtual network named VNet1.

You need to implement Azure Extended Network. The solution must minimize costs.

Which type of virtual machine should you deploy to VNet1, and which tool should you use to configure Azure Extended Network? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 33

Options:

Buy Now
Questions 34

You have an Azure virtual machine named VM1.

You need to capture all the network traffic of VM1 by using Azure Network Watcher. To which locations can the capture be written?

Options:

A.

a file path on VM1 only

B.

General purpose v2 standard only

C.

a Block blob premium account only

D.

General purpose v2 standard and a file path on VM1 only

E.

General purpose v2 standard and a Block blob premium account only

F.

blob storage, a file path on VM1, and a Block blob premium account

Buy Now
Questions 35

You have 10 Azure App Service instances. Each instance hosts the same web app. Each instance is in a different Azure region.

You need to configure Azure Traffic Manager to direct users to the instance that has the lowest latency.

Which routing method should you use?

Options:

A.

geographic

B.

weighted

C.

performance

D.

priority

Buy Now
Questions 36

You need to plan the deployment of LBGW1. The solution must support the planned changes.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 36

Options:

Buy Now
Questions 37

You need to configure APPGW1 to support end-to-end encryption. The solution must meet the security requirements. What should you do?

Options:

A.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA and includes the full certificate chain.

B.

From the Backend settings, upload a wildcard TLS certificate that has a private key issued by the internal root CA

C.

From the Backend settings, upload the internal root CA certificate.

D.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA.

Buy Now
Questions 38

Your on-premises network contains a DNS server named Server 1.

You have an Azure subscription that contains the resources shown in the following table.

AZ-700 Question 38

The on-premises network is connected to VNet1 by using a Site-to-Site (S2S) VPN.

You need to ensure that Server1 can resolve the DNS name of storage1. The solution must minimize costs and administrative effort.

What should you use?

Options:

A.

an Azure Private DNS zone

B.

an Azure virtual machine that hosts a DNS service

C.

an Azure public DNS zone

D.

Azure DNS Private Resolver

Buy Now
Questions 39

You need to configure the default route in Vnet2 and Vnet3. The solution must meet the virtual networking requirements.

What should you use to configure the default route?

Options:

A.

a user-defined route assigned to GatewaySubnet in Vnet2 and Vnet3

B.

a user-defined route assigned to GatewaySubnet in Vnet1

C.

BGP route exchange

D.

route filters

Buy Now
Questions 40

You have art Azure subscription.

You plan to deploy Azure Front Door with Azure Web Application Firewall (WAF).

You plan to implement custom rules and managed rules that meet the following requirements:

• Block malicious bots.

• Throttle client IP addresses that exceed 100 connections per minute.

You need to identify which Front Door SKU to configure, and which type of rule to configure for each requirement. The solution must minimize administrative effort and costs.

What should identify? To answer, drag the appropriate options to the correct targets. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

AZ-700 Question 40

Options:

Buy Now
Questions 41

You need to identify which IP address space to allocate for the planned deployment of PRDNS1 to HubVNet and SpokeVNet. The solution must meet the general requirements

What should you identify for each virtual network? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

AZ-700 Question 41

Options:

Buy Now
Questions 42

You ate configuring the DNS forwarding luleset for DNSR1

You need to configure the destination IP address for azure.proseware.com and for corp.proseware.com. The solution must meet the general requirements.

Which IP addiesses should you configure for each namespace? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 42

Options:

Buy Now
Questions 43

You need to manage connectivity from NYCNet to the Azure services that use private endpoints. The solution must meet the security requirements. What should you do first?

Options:

A.

Add a route table to SUBNET-PL

B.

Enable a network policy for SUBNET-PE.

C.

From Azure Virtual Network Manager, create a security admin configuration.

D.

From Azure Viitual Network Manager, create a network group that has Member type set to Subnet

Buy Now
Questions 44

You need to deploy Azure Virtual Network Manager. The solution must support the planned changes and meet the connectivity requirements.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-700 Question 44

Options:

Buy Now
Questions 45

You need to configure the P2S VPN to meet the connectivity requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 45

Options:

Buy Now
Questions 46

You need to configure a custom rule for APPGWI-WAFPolicy to allow only connections that originate from FD1. The solution must support the planned changes.

Which Match type and Match variable should you select?

Options:

A.

String and RequestCookies

B.

IP address and RemoteAddr

C.

String and RequestHeaders

D.

Geo location and RemoteAddr

Buy Now
Questions 47

You need to configure connectivity between NYCNet and SFONet. The solution must meet the connectivity requirements. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

AZ-700 Question 47

Options:

Buy Now
Questions 48

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 48

Options:

Buy Now
Questions 49

Which virtual machines can VM1 and VM4 ping successfully? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 49

Options:

Buy Now
Questions 50

You create NSG10 and NSG11 to meet the network security requirements.

For each of the following statements, select Yes it the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 50

Options:

Buy Now
Questions 51

You need to configure GW1 to meet the network security requirements for the P2S VPN users.

Which Tunnel type should you select in the Point-to-site configuration settings of GW1?

Options:

A.

IKEv2 and OpenVPN (SSL)

B.

IKEv2

C.

IKEv2 and SSTP (SSL)

D.

OpenVPN (SSL)

E.

SSTP (SSL)

Buy Now
Questions 52

What should you implement to meet the virtual network requirements for the virtual machines that connect to Vnet4 and Vnet5?

Options:

A.

a private endpoint

B.

a virtual network peering

C.

a private link service

D.

a routing table

E.

a service endpoint

Buy Now
Questions 53

You are implementing the virtual network requirements for VM Analyze.

What should you include in a custom route that is linked to Subnet2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 53

Options:

Buy Now
Questions 54

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-700 Question 54

Options:

Buy Now
Questions 55

You are implementing the Virtual network requirements for Vnet6.

What is the minimum number of subnets and service endpoints you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 55

Options:

Buy Now
Questions 56

You need to meet the network security requirements for the NSG flow logs.

Which type of resource do you need, and how many instances should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 56

Options:

Buy Now
Questions 57

In which NSGs can you use ASG1 and to which virtual machine network interfaces can you associate ASG1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 57

Options:

Buy Now
Exam Code: AZ-700
Exam Name: Designing and Implementing Microsoft Azure Networking Solutions
Last Update: Apr 6, 2026
Questions: 312

PDF + Testing Engine

$52.5  $174.99

Testing Engine

$40.5  $134.99
buy now AZ-700 testing engine

PDF (Q&A)

$34.5  $114.99
buy now AZ-700 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 06 Apr 2026