{"id":18088,"date":"2026-09-22T05:18:48","date_gmt":"2026-09-22T05:18:48","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18088"},"modified":"2026-09-22T05:18:48","modified_gmt":"2026-09-22T05:18:48","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which Azure networking service can provide centralized connectivity between branch offices, remote users, and Azure virtual networks through a managed WAN architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN provides a managed wide-area networking architecture that can connect branch offices, remote users, and Azure virtual networks through virtual hubs. It can simplify large-scale connectivity and routing by reducing the need to manually maintain many individual connections. Azure DNS handles name resolution, Load Balancer distributes network traffic, and Bastion provides secure administrative access. Virtual WAN should be designed around organizational topology, regional requirements, routing policies, security services, branch connectivity, and expected network growth to provide scalable and manageable enterprise connectivity.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which Azure service allows a private endpoint to connect securely to a supported Azure PaaS resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Network Watcher<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private Link provides private connectivity between a virtual network and supported Azure services through private endpoints. The private endpoint receives a private IP address from the virtual network, allowing applications to reach the service without requiring a publicly exposed endpoint. Traffic Manager performs DNS-based routing, Network Watcher provides diagnostics, and Route Server supports dynamic routing. Private Link should be integrated with appropriate DNS resolution, network security controls, identity permissions, and service configurations. This architecture is useful for workloads that require stronger network isolation.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which Azure service can inspect HTTP requests and protect web applications from common attacks such as SQL injection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Application Firewall provides application-layer protection for HTTP and HTTPS traffic. Its managed rule sets can help detect and block common web attacks, including SQL injection and cross-site scripting. WAF can be integrated with supported Azure services such as Application Gateway and Azure Front Door. Route Server manages routing, VPN Gateway provides network connectivity, and DNS handles name resolution. WAF rules should be monitored and tuned to the application&#8217;s legitimate traffic patterns. It should complement secure coding, authentication, authorization, vulnerability management, and other application security practices.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>An organization needs to connect a virtual network to an on-premises network through an encrypted Internet-based tunnel. Which service should be deployed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure VPN Gateway provides encrypted connectivity between Azure virtual networks and on-premises or other remote networks using VPN technologies. A site-to-site VPN is commonly used when an organization needs to connect an entire network to Azure over the Internet. Front Door provides global application delivery, Traffic Manager provides DNS-based traffic routing, and Load Balancer distributes network traffic. VPN architecture should include appropriate address spaces, authentication, routing, gateway configuration, redundancy, and bandwidth planning. Network security controls should also restrict access to required resources.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which Azure service provides DNS-based routing that can distribute application requests using a weighted percentage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Traffic Manager supports weighted traffic routing, allowing administrators to assign relative weights to endpoints. DNS responses can then distribute client requests according to those configured weights. This capability can be useful for gradual migrations, traffic distribution, testing, or controlled transitions between application deployments. Azure Firewall provides traffic filtering, Bastion provides administrative connectivity, and Private DNS supports private name resolution. Because Traffic Manager operates through DNS, administrators should account for DNS caching and client behavior when evaluating the actual distribution of requests.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which Azure resource controls traffic at the subnet or network interface level by using inbound and outbound security rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group contains inbound and outbound security rules that control network traffic associated with subnets and network interfaces. Rules can evaluate source and destination addresses, ports, protocols, and direction. NSGs are useful for implementing workload-level network restrictions and segmentation. Route Server provides dynamic routing capabilities, Traffic Manager performs DNS-based routing, and Front Door provides global application delivery. NSG rules should be narrowly scoped to required communication and should be reviewed whenever application dependencies or network architecture change.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which Azure service provides centralized network traffic filtering and supports application-level rules for Internet-bound traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall provides centralized, stateful network traffic filtering for Azure environments. It can enforce network and application-level rules and can be used to control traffic flowing between workloads, networks, and Internet destinations. Azure DNS handles name resolution, Bastion provides secure virtual machine administration, and Route Server supports dynamic route exchange. Azure Firewall can be deployed within centralized network architectures such as a hub-and-spoke model. Administrators should monitor firewall logs, maintain documented policies, and regularly review rules for unnecessary or overly broad access.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which Azure networking architecture is most suitable for connecting multiple isolated workload networks to shared services such as Azure Firewall and VPN Gateway?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat virtual network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Internet architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture separates shared network services from individual workload networks. The hub can host services such as Azure Firewall, VPN Gateway, Bastion, and centralized DNS components, while spoke virtual networks contain specific applications or workloads. This design provides a structured approach to segmentation and shared service access. A flat network or single subnet provides fewer isolation boundaries, while public Internet connectivity can increase exposure. Hub-and-spoke deployments require appropriate peering, route tables, security rules, and centralized traffic inspection to maintain secure connectivity.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which Azure networking capability allows administrators to create custom routes that override applicable system routing behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User-defined routes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User-defined routes allow administrators to specify custom next-hop behavior for traffic within Azure virtual networks. They can be used to direct traffic toward network virtual appliances, virtual network gateways, or other supported destinations. This capability is important for architectures requiring centralized inspection, custom routing, or hybrid connectivity. Public IP prefixes manage public addressing, private DNS zones provide name resolution, and service endpoints provide optimized access to supported Azure services. Custom routing should be carefully tested because incorrect routes can cause connectivity failures or bypass intended security controls.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which Azure service is used to provide secure browser-based administrative connectivity to virtual machines without assigning public IP addresses to those machines?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Bastion provides browser-based RDP and SSH connectivity to virtual machines through the Azure portal. It can reduce the need to assign public IP addresses to individual virtual machines and helps limit direct exposure of administrative ports to the Internet. Traffic Manager provides DNS-based routing, Azure DNS handles name resolution, and Load Balancer distributes network traffic. Bastion should be secured through strong identity controls and least-privilege access. Administrative access should also be monitored and restricted to approved users, devices, and operational requirements.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which Azure networking service can provide global routing for HTTP and HTTPS applications while using health-based origin selection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Network Watcher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door provides global Layer 7 application delivery and can route HTTP and HTTPS requests to healthy backend origins. It can support globally distributed applications by using health probes and routing configurations to direct users toward appropriate origins. Route Server handles dynamic routing, VPN Gateway provides private connectivity, and Network Watcher provides network diagnostics. Front Door should be designed with appropriate origin groups, health probes, routing rules, custom domains, TLS configuration, and security policies. It is particularly useful for globally distributed web applications.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which Azure capability helps administrators determine whether a route or security configuration is responsible for a failed connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher diagnostics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Network Watcher provides several diagnostic capabilities that help identify network connectivity problems. Administrators can inspect effective routes, effective security rules, next-hop behavior, IP flow decisions, and connection monitoring results. These tools help distinguish routing problems from security-rule issues and other connectivity failures. Traffic Manager provides DNS-based application routing, Private Link provides private connectivity, and Azure DNS manages name resolution. Network diagnostics should be used systematically by checking the expected path, applicable security rules, routing behavior, DNS resolution, and endpoint availability.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which Azure service provides a private DNS zone that can be linked to multiple virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private DNS allows organizations to create private DNS zones and link them to virtual networks for internal name resolution. A private DNS zone can support multiple virtual networks when appropriately configured, helping applications resolve internal names consistently across a distributed Azure environment. Traffic Manager provides DNS-based application routing, Load Balancer distributes network traffic, and Azure Firewall provides network filtering. Private DNS architecture should define zone ownership, record management, virtual network links, hybrid resolution requirements, and procedures for maintaining accurate internal DNS records.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which Azure feature is most appropriate for reserving a contiguous group of public IP addresses for an enterprise deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Network Watcher<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS Private Resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A public IP prefix reserves a contiguous range of public IP addresses that can be assigned to supported Azure resources. This can simplify public address planning when an organization requires multiple public endpoints and wants predictable address allocation. Network Watcher provides diagnostics, Bastion provides administrative access, and DNS Private Resolver provides hybrid DNS resolution. Public IP allocation should be carefully controlled because each public endpoint can increase exposure. Organizations should document why public addresses are required and protect associated resources with appropriate network security controls.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which connectivity option provides encrypted VPN access from individual client computers to an Azure virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global virtual network peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Point-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Site-to-site VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Point-to-site VPN provides an encrypted connection between individual client devices and an Azure virtual network. It is useful for remote users or administrators who require secure access to Azure resources without connecting an entire corporate network. Site-to-site VPN connects networks rather than individual clients, ExpressRoute provides private connectivity through a connectivity provider, and virtual network peering connects Azure virtual networks. Point-to-site architecture should define authentication, client address allocation, routing, access restrictions, and the specific resources remote users are permitted to reach.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which Azure networking service supports private connectivity to PaaS resources through a private endpoint and private IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private Link enables private connectivity between virtual networks and supported platform services through private endpoints. A private endpoint creates a network interface with a private IP address in the virtual network, allowing applications to access the service without relying on a publicly reachable endpoint. Traffic Manager provides DNS-based routing, Load Balancer distributes network traffic, and Route Server supports dynamic routing. Private Link designs should include DNS integration, subnet planning, service authorization, network security rules, and monitoring to ensure that private connectivity is both functional and appropriately controlled.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which Azure routing feature is automatically created to provide basic connectivity between resources in a virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User-defined route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure automatically creates system routes to provide fundamental connectivity between resources and supported network destinations. These routes are part of Azure&#8217;s default routing behavior and can be supplemented or influenced by user-defined routes. User-defined routes are manually created when custom forwarding is required. Application and firewall routes are not standard Azure route categories. Understanding system routes is essential when designing custom routing because administrators need to know how Azure&#8217;s default routes interact with custom routes and how route precedence affects the actual traffic path.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which Azure service can provide dynamic route exchange with network virtual appliances using BGP?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Route Server provides managed BGP route exchange between Azure virtual networks and compatible network virtual appliances. It allows supported appliances to dynamically advertise routes to Azure and learn routes from Azure, reducing the need to manually configure static routes for certain architectures. Traffic Manager provides DNS-based routing, Azure DNS handles name resolution, and Bastion provides secure administrative access. Route Server should be incorporated carefully into the routing architecture, with attention to advertised prefixes, network appliance behavior, failover, and traffic inspection requirements.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which Azure service can provide network-level connectivity monitoring between a virtual machine and another endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher Connection Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Connection Monitor continuously evaluates connectivity between supported source and destination endpoints. It can provide information about connectivity status and help identify performance or reachability problems. Azure Firewall controls network traffic, Private DNS handles name resolution, and Traffic Manager provides DNS-based application routing. Connection Monitor is useful for validating expected network paths and detecting failures after deployment. Administrators can use monitoring results to investigate routing, security rules, DNS dependencies, endpoint availability, and other conditions affecting communication.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which principle should be applied when exposing an Azure workload to the public Internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give every resource a public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted inbound traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Minimize public exposure and apply layered security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable network monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Public Internet exposure should be minimized because publicly reachable resources have a larger attack surface. Only resources that genuinely require Internet accessibility should be exposed, and they should be protected using layered controls such as WAF, network security rules, Azure Firewall, DDoS protection, secure authentication, monitoring, and appropriate segmentation. Assigning public IP addresses broadly or allowing unrestricted inbound traffic increases risk. Disabling monitoring removes important visibility. A secure architecture begins by identifying the required public traffic and then applying the smallest necessary exposure with multiple complementary controls.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which Azure networking service can provide centralized connectivity between branch offices, remote users, and Azure virtual networks through a managed WAN architecture? Azure Virtual WAN Azure DNS Azure Load Balancer Azure Bastion Correct Answer: 1 Explanation Azure Virtual WAN provides a managed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18088"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18088"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18088\/revisions"}],"predecessor-version":[{"id":18089,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18088\/revisions\/18089"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}