Designing and Implementing Microsoft Azure Networking Solutions Free Sample Questions

20 free sample questions258 in the full practice test Other version: 98-366(50)

Try simulator

AZ-700 Sample Questions

  1. Question 1

    A financial services company is designing a network architecture in Azure to host a new algorithmic trading platform. A key requirement is to ensure that traffic from the application servers in one subnet (AppSubnet) is always inspected by a Network Virtual Appliance (NVA) before reaching the database servers in another subnet (DataSubnet) within the same VNet. Which of the following is the most effective way to enforce this traffic flow without altering the VNet's address space?

    Answer and explanation

    Correct answer: C

    The correct method to force traffic between subnets through a Network Virtual Appliance (NVA) is called service chaining, which is implemented using User-Defined Routes (UDRs). By creating a route table and associating it with the source subnet (AppSubnet), you can define a custom route for traffic destined for the target subnet (DataSubnet). Setting the next hop type to 'VirtualAppliance' and specifying the NVA's private IP address ensures that all traffic matching the route is sent to the NVA for inspection first. NSGs control access but do not redirect traffic flow. VNet peering is for connecting separate VNets, not subnets within the same VNet.

  2. Question 2

    A retail company is expanding its e-commerce platform, which is hosted entirely in Azure. They have multiple VNets across several Azure regions (East US, West Europe, Southeast Asia). The security team requires a centralized method to manage and apply consistent firewall rules and security policies across all VNets, including those in a hub-and-spoke topology. Which Azure service is specifically designed to meet this requirement for centralized policy management and deployment of secured virtual hubs?

    Answer and explanation

    Correct answer: B

    Azure Firewall Manager is the correct service for this scenario. It provides a centralized security policy and route management for cloud-based security perimeters. It is specifically designed to manage Azure Firewall policies across multiple secured virtual hubs (in a Virtual WAN context) or hub virtual networks. This allows for consistent security policy enforcement globally. While Azure Policy can enforce deployment standards and Network Watcher provides monitoring, neither offers the centralized firewall rule management that Firewall Manager does.

  3. Question 3

    A media company uses Azure Application Gateway v2 to protect its web applications. To enhance security, a Web Application Firewall (WAF) policy has been implemented in Prevention mode. During a recent feature launch, legitimate users reported that their search queries containing special characters (e.g., 'O'Malley') are being blocked. A review of the WAF logs confirms that rule 942100 (SQL Injection Attack) from the OWASP 3.1 ruleset is being triggered. What is the most precise and secure method to resolve this issue while minimizing the attack surface?

    Answer and explanation

    Correct answer: D

    The best practice for handling a false positive in WAF is to be as specific as possible to avoid weakening security. Creating a per-rule exclusion is the most precise method. By specifying the rule ID (942100) and limiting the exclusion to the specific request argument name (e.g., 'search_query'), you are telling the WAF to ignore this specific SQL injection check only for that parameter, while keeping the rule active for all other parts of the request. Disabling the rule entirely or switching to Detection mode would significantly increase the security risk. A custom allow rule for apostrophes is too broad and could be exploited.

  4. Question 4

    Multiple answers

    A manufacturing firm is migrating a legacy application to Azure. The application's backend consists of several virtual machines that do not have public IP addresses and must not be exposed to the internet. However, these VMs need to initiate outbound connections to the internet to download software updates from specific vendor websites. You need to provide a secure and scalable solution for this outbound connectivity. Which Azure service should you implement? (Select TWO that apply)

    Answer and explanation

    Correct answers: A, C

    Both Azure NAT Gateway and Azure Firewall are excellent solutions for providing secure, managed outbound internet access for private VMs. Azure NAT Gateway is a fully managed and highly resilient service that simplifies outbound-only internet connectivity for virtual networks. It's easy to set up and provides scalable SNAT capabilities. Azure Firewall provides the same outbound SNAT capability but adds a layer of security by allowing you to define FQDN-based application rules, ensuring the VMs can only connect to the approved vendor websites and not the entire internet. The choice between them depends on whether simple NAT or full-featured firewalling is required.

  5. Question 5

    A healthcare provider is deploying an Azure SQL Database. Due to strict compliance requirements (HIPAA), all network traffic to the database must originate from their private virtual network and must never traverse the public internet. They also need to ensure that their on-premises data analysis tools can connect to the Azure SQL Database securely over an existing ExpressRoute connection. Which Azure networking feature should be implemented to meet these requirements?

    Answer and explanation

    Correct answer: B

    An Azure Private Endpoint is the correct solution. It creates a network interface within your VNet with a private IP address, effectively bringing the Azure SQL Database into your private network. This ensures traffic from the VNet to the database stays on the Microsoft backbone. Crucially, because the database now has a private IP in the VNet, on-premises resources connected via ExpressRoute or VPN can resolve and connect to it privately. A VNet Service Endpoint also keeps traffic on the Azure backbone but does not provide a private IP in the VNet, making it inaccessible directly from on-premises without additional configuration like NAT.

  6. Question 6

    An organization is deploying a multi-tier application in a single VNet with three subnets: Web, App, and Data. The security policy states that the Web subnet can communicate with the App subnet, and the App subnet can communicate with the Data subnet. However, direct communication from the Web subnet to the Data subnet must be explicitly blocked. Which is the most efficient way to implement this policy using Application Security Groups (ASGs)?

    Answer and explanation

    Correct answer: B

    Using Application Security Groups (ASGs) is the most efficient and scalable solution. By creating an ASG for each application tier (WebASG, AppASG, DataASG) and associating the VM NICs accordingly, you can define NSG rules based on these logical groups rather than explicit IP addresses. A single NSG can be applied to all subnets with rules like: 'Allow traffic from source WebASG to destination AppASG' and 'Deny traffic from source WebASG to destination DataASG'. This simplifies management, as you don't need to update IP addresses in the NSG rules when VMs are added or removed.

  7. Question 7

    You are designing a hybrid connectivity solution for a company with a main office in New York and a branch office in London. Both offices need to connect to Azure resources located in the East US and UK South regions, respectively. A key requirement is that the on-premises network in London must be able to communicate directly with the on-premises network in New York over the Microsoft backbone to avoid traversing the public internet. Which ExpressRoute feature is specifically designed to enable this on-premises to on-premises connectivity?

    Answer and explanation

    Correct answer: D

    ExpressRoute Global Reach is designed for this exact scenario. It allows you to link ExpressRoute circuits together to make a private network between your on-premises locations, using the Microsoft global network as the backbone. This enables direct connectivity between the New York and London offices without the traffic having to hairpin through a VNet in Azure or traverse the public internet. The Premium Add-on is required for global connectivity to Azure services, but Global Reach is the specific feature for on-premises to on-premises communication.

  8. Question 8

    True or False: When configuring a VNet peering between two virtual networks in different Azure regions (Global VNet Peering), the data transfer costs are the same as for peering within the same region.

    Answer and explanation

    Correct answer: B

    This statement is false. Data transfer costs for Global VNet Peering (across regions) are different and typically higher than for VNet peering within the same region. For regional VNet peering, both ingress and egress traffic are charged. For Global VNet Peering, traffic is charged at zonal data transfer rates, which vary based on the Azure zones the data is traversing.

  9. Question 9

    Multiple answers

    An administrator is troubleshooting a connectivity issue where a virtual machine (VM1) in VNetA cannot connect to another virtual machine (VM2) in VNetB on port 3389. The VNets are peered. Using Azure Network Watcher, the administrator runs an IP Flow Verify test from VM1 to VM2. The result indicates 'Access Denied'. What are the TWO most likely causes for this result? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    IP Flow Verify checks if a packet is allowed or denied to or from a virtual machine based on the effective security rules. An 'Access Denied' result directly points to a Network Security Group (NSG) rule blocking the traffic. The block could be on the outbound path from the source VM (VM1) or on the inbound path to the destination VM (VM2). While a disabled peering or incorrect routing would cause a failure, they would typically result in a 'Traffic is not routable' or similar error, not 'Access Denied'.

  10. Question 10

    A university provides a custom application to its students, hosted on virtual machines in Azure. The application must be accessible from anywhere on the internet. To ensure high availability and optimal performance, instances of the application are deployed in two Azure regions: East US and West Europe. You need to configure a solution that directs users to the geographically closest region. If the application in the closest region becomes unavailable, users must be automatically redirected to the other healthy region. Which Azure service is the best fit for these requirements?

    Answer and explanation

    Correct answer: C

    Azure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute traffic optimally to services across global Azure regions. The 'Performance' routing method is specifically designed to route traffic to the endpoint that has the lowest network latency from the client's perspective, effectively sending them to the 'closest' region. It also includes built-in endpoint health monitoring and automatic failover, which satisfies the requirement to redirect users if one region becomes unavailable. Azure Load Balancer and Application Gateway are regional services and cannot perform DNS-based global routing on their own.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 308 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon