{"id":18092,"date":"2026-09-22T05:21:32","date_gmt":"2026-09-22T05:21:32","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18092"},"modified":"2026-09-22T05:21:32","modified_gmt":"2026-09-22T05:21:32","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 121<\/b><\/h3>\n<p><b>Which Azure service can provide centralized connectivity and routing between multiple Azure virtual networks, branches, and remote users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN provides a managed networking architecture for connecting Azure virtual networks, branch locations, and remote users through virtual hubs. It can simplify large-scale connectivity by providing centralized routing and connectivity management. Organizations can also integrate supported security solutions with Virtual WAN to create secured hub architectures. Azure DNS handles name resolution, Bastion provides administrative access, and Load Balancer distributes traffic. When designing Virtual WAN, administrators should consider hub placement, routing requirements, branch connectivity, security inspection, regional coverage, and expected network growth.<\/span><\/p>\n<h3><b>Question 122<\/b><\/h3>\n<p><b>An organization wants traffic entering a Virtual WAN hub to be inspected by Azure Firewall before reaching connected networks. Which architecture should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat virtual network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secured virtual hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standalone subnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secured virtual hub integrates Azure Firewall with an Azure Virtual WAN hub to provide centralized security inspection and traffic control. This architecture can help organizations apply consistent security policies to traffic flowing through the hub and connected networks. A flat network does not provide the same centralized structure, while DNS zones and standalone subnets serve different purposes. A secured virtual hub should be designed with appropriate routing intent, firewall policies, connectivity requirements, and regional considerations to ensure traffic follows the intended inspection path.<\/span><\/p>\n<h3><b>Question 123<\/b><\/h3>\n<p><b>Which Azure networking service is primarily responsible for resolving names for resources that are accessible only through private network addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private DNS provides name resolution for private resources within Azure virtual networks. It allows organizations to create private DNS zones and associate them with virtual networks so that workloads can resolve internal names without depending on publicly accessible DNS records. Front Door provides global application delivery, Traffic Manager performs DNS-based endpoint routing, and Load Balancer distributes network traffic. Private DNS should be planned together with private endpoints, virtual network links, hybrid DNS, and record management to ensure that applications consistently resolve the correct private addresses.<\/span><\/p>\n<h3><b>Question 124<\/b><\/h3>\n<p><b>Which Application Gateway feature can keep existing connections active for a short period when a backend server is being removed from service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP propagation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connection draining allows Application Gateway to stop sending new connections to a backend instance while allowing existing connections to complete for a configured period. This is useful during maintenance, scaling, or backend replacement because active users can have their existing sessions completed more gracefully. BGP propagation concerns routing, DNS forwarding concerns name resolution, and SNAT translates source addresses. Connection draining should be considered when applications maintain long-lived connections or sessions, particularly during planned deployments where abrupt termination could interrupt active users.<\/span><\/p>\n<h3><b>Question 125<\/b><\/h3>\n<p><b>Which Azure networking feature allows administrators to associate a security rule with a group of virtual machines based on their application role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Security Groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefixes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Security Groups, or ASGs, allow administrators to group virtual machine network interfaces according to application roles and then reference those groups in Network Security Group rules. This can make security policies easier to manage because rules can describe application relationships rather than relying only on individual IP addresses. Public IP prefixes manage public addressing, Route Server supports dynamic routing, and NAT Gateway provides outbound connectivity. ASGs are especially useful in environments where application tiers change over time and security rules should remain aligned with logical workload roles.<\/span><\/p>\n<h3><b>Question 126<\/b><\/h3>\n<p><b>Which Azure feature can simplify Network Security Group rules by representing groups of Azure service IP addresses with predefined identifiers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS zones<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route tables<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service tags represent groups of IP address prefixes associated with Azure services and can be used in supported Network Security Group rules. They reduce the need to manually maintain large lists of service IP addresses when controlling traffic to or from supported Azure services. Private endpoints provide private connectivity, DNS zones manage name resolution, and route tables control network paths. Service tags should still be used carefully because each tag has a defined scope, and administrators should verify that the selected tag represents exactly the traffic that the security policy intends to permit.<\/span><\/p>\n<h3><b>Question 127<\/b><\/h3>\n<p><b>A security administrator creates two NSG rules with the same direction and matching traffic criteria. One has priority 200 and the other has priority 400. Which rule is evaluated first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority 400<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority 600<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority 200<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Both rules simultaneously<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Security Group rules are processed according to priority, with lower numerical values evaluated before higher numerical values. Therefore, a rule with priority 200 is evaluated before a rule with priority 400 when both apply to the same traffic direction and conditions. If an applicable rule allows or denies the traffic, later rules may not be reached. Administrators should assign priorities deliberately and maintain clear documentation to avoid accidental access. Default NSG rules are evaluated after custom rules because their priorities are lower in precedence.<\/span><\/p>\n<h3><b>Question 128<\/b><\/h3>\n<p><b>Which Azure networking capability can provide a visual representation of network resources and their relationships for troubleshooting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher topology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher topology provides a visual representation of resources and network relationships within an Azure subscription or resource group context. It can help administrators understand connections between virtual networks, subnets, network interfaces, virtual machines, and other supported resources. Traffic Manager provides DNS-based routing, Azure DNS manages name resolution, and NAT Gateway provides outbound translation. Topology information is useful during troubleshooting because it can reveal unexpected relationships or missing connectivity components. It should be combined with route, security, and connection diagnostics for deeper investigation.<\/span><\/p>\n<h3><b>Question 129<\/b><\/h3>\n<p><b>Which Azure networking service can provide a private connection between a consumer virtual network and a privately exposed service owned by another organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private Link allows consumers to privately access supported services through private endpoints. This includes scenarios where a service provider exposes its own service through a Private Link service. The consumer accesses the service using a private IP address from its virtual network rather than depending on public Internet connectivity. Bastion provides virtual machine administration, Traffic Manager provides DNS-based routing, and Azure DNS handles name resolution. Private Link designs should address approval workflows, DNS resolution, access permissions, IP address allocation, and provider-consumer connectivity requirements.<\/span><\/p>\n<h3><b>Question 130<\/b><\/h3>\n<p><b>Which Azure service provides a managed network address translation function for outbound traffic from a subnet without requiring a public IP on each virtual machine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure NAT Gateway provides managed source network address translation for outbound Internet traffic from resources in an associated subnet. Virtual machines can use the NAT Gateway&#8217;s public IP addresses for outbound connections without requiring individual public IP assignments. Firewall Manager manages security policies and supported firewall deployments, Route Server handles dynamic routing, and Bastion provides administrative access. NAT Gateway is useful when predictable outbound IP addresses and scalable SNAT capacity are needed. Administrators should still control inbound access separately because NAT Gateway does not provide inbound Internet connectivity.<\/span><\/p>\n<h3><b>Question 131<\/b><\/h3>\n<p><b>Which ExpressRoute component provides the Layer 3 connectivity between an Azure virtual network and an ExpressRoute circuit?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute virtual network gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An ExpressRoute virtual network gateway connects an Azure virtual network to an ExpressRoute circuit and enables private connectivity through the ExpressRoute architecture. The gateway participates in the routing process required to exchange network traffic between Azure and the connected private network. Application Gateway provides application-layer traffic distribution, Bastion provides administrative connectivity, and Network Watcher supplies diagnostics. ExpressRoute gateway planning should account for supported gateway SKUs, circuit bandwidth, regional architecture, redundancy, routing requirements, and the number of virtual networks that need connectivity.<\/span><\/p>\n<h3><b>Question 132<\/b><\/h3>\n<p><b>Which Azure VPN Gateway capability allows an administrator to use BGP to dynamically exchange routes with an on-premises VPN device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPN Gateway supports Border Gateway Protocol, or BGP, for dynamic route exchange in supported VPN configurations. Instead of relying entirely on manually configured static routes, BGP can advertise and learn routes between Azure and compatible on-premises devices. This can simplify route management in larger hybrid environments and improve adaptability when network prefixes change. DNS forwarding handles name resolution, WAF policies protect web applications, and connection draining manages backend connections. BGP deployments require compatible autonomous system configurations, appropriate peering addresses, and careful route advertisement planning.<\/span><\/p>\n<h3><b>Question 133<\/b><\/h3>\n<p><b>Which Azure Virtual Network Manager configuration is intended to create connectivity between selected virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connectivity configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rewrite configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual Network Manager connectivity configurations define how selected virtual networks should connect within a managed network architecture. Administrators can use network groups as the scope for applying connectivity configurations, helping standardize network relationships across large environments. Rewrite configurations are associated with application traffic manipulation, WAF configurations protect web applications, and NAT configurations are not the primary Virtual Network Manager connectivity mechanism. Connectivity designs should consider network groups, topology requirements, address spaces, security boundaries, regional scope, and whether networks require full or limited communication.<\/span><\/p>\n<h3><b>Question 134<\/b><\/h3>\n<p><b>Which Azure Front Door capability can reduce repeated requests to an origin by serving eligible content from edge locations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route propagation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door caching allows eligible content to be served from edge locations instead of requiring every request to reach the backend origin. This can reduce origin load and improve response times for cached content distributed across geographically separated users. BGP handles route exchange, DNAT translates destination addresses, and route propagation concerns network routing. Caching behavior depends on request and response characteristics, cache-control settings, and Front Door configuration. Administrators should ensure that only suitable content is cached and that dynamic or sensitive content is handled appropriately.<\/span><\/p>\n<h3><b>Question 135<\/b><\/h3>\n<p><b>Which Azure Firewall feature allows administrators to organize security policies so that common settings can be inherited by multiple child policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy inheritance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS autoregistration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall Policy supports inheritance, allowing child policies to inherit relevant configurations from a parent policy. This can help organizations establish common security requirements while allowing individual environments or business units to maintain additional rules appropriate to their workloads. DNS autoregistration manages DNS records, connection draining controls backend connection behavior, and gateway transit enables shared gateway access across peered virtual networks. Policy inheritance can improve consistency, but administrators should clearly define ownership, precedence, exceptions, and change-management procedures to prevent unintended security behavior.<\/span><\/p>\n<h3><b>Question 136<\/b><\/h3>\n<p><b>Which Azure networking design consideration is most important when creating address spaces for several interconnected virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use overlapping address ranges whenever possible<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ensure address spaces are planned to avoid overlap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign the same subnet to every workload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoid documenting IP allocations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Non-overlapping address spaces are essential when designing interconnected Azure virtual networks. Overlapping IP ranges can create routing ambiguity and prevent or complicate connectivity between networks, particularly when using peering, VPN, or ExpressRoute. Address planning should account for current workloads as well as future expansion, hybrid connectivity, subnet requirements, and organizational boundaries. Using identical subnet ranges everywhere can create significant integration problems. A documented IP addressing strategy provides a foundation for scalable routing, security policies, DNS design, and future network expansion.<\/span><\/p>\n<h3><b>Question 137<\/b><\/h3>\n<p><b>Which Azure Load Balancer option can preserve the original destination IP and port information when forwarding traffic to a backend instance in supported scenarios?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Floating IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Floating IP is an Azure Load Balancer capability that can preserve or provide the frontend IP configuration to the backend in supported scenarios, such as certain network virtual appliance architectures. This can be useful when applications or appliances need to process traffic using the frontend address rather than a translated destination address. Weighted routing is associated with Traffic Manager, DNS forwarding manages name resolution, and service tags simplify NSG rules. Floating IP configurations require careful consideration of backend behavior, health probes, application requirements, and network appliance design.<\/span><\/p>\n<h3><b>Question 138<\/b><\/h3>\n<p><b>Which Azure networking feature allows a virtual network to use the gateway of a peered virtual network for connectivity to another network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Gateway transit allows a virtual network that is peered with another virtual network to use the remote network&#8217;s VPN or ExpressRoute gateway for supported connectivity scenarios. This can reduce the need to deploy separate gateways in every connected virtual network. The configuration involves appropriate peering settings on both sides and must match the desired gateway architecture. DNS caching, WAF prevention, and connection monitoring address different networking requirements. Gateway transit is particularly useful in hub-and-spoke environments where centralized hybrid connectivity is provided from the hub.<\/span><\/p>\n<h3><b>Question 139<\/b><\/h3>\n<p><b>Which Azure Front Door feature determines whether an origin is available before directing application traffic to it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Health probes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSG priorities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UDRs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP communities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door uses health probes to evaluate the availability of configured origins. The results help Front Door determine which origins are healthy and eligible to receive traffic according to the configured routing behavior. This supports resilient application delivery when multiple backend origins are available. NSG priorities control network security rule processing, UDRs influence IP routing, and BGP communities are routing attributes rather than Front Door health mechanisms. Health probe paths, intervals, protocols, and expected responses should be configured carefully so that unhealthy origins are detected without creating unnecessary monitoring traffic.<\/span><\/p>\n<h3><b>Question 140<\/b><\/h3>\n<p><b>A company is designing a hybrid Azure network and needs predictable private connectivity, dynamic routing, and redundant network paths. Which planning approach is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use public IP addresses for all hybrid connections<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Design ExpressRoute or VPN connectivity with appropriate routing and redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable route exchange to simplify troubleshooting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Place every workload in one subnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hybrid network design should account for private connectivity, routing behavior, redundancy, security, and operational requirements. ExpressRoute can provide private connectivity through a provider, while VPN Gateway can provide encrypted connectivity over the Internet. Depending on the architecture, BGP can provide dynamic route exchange and redundant paths can improve resilience. Public IP addresses should not be used as a substitute for appropriate private connectivity, and placing every workload in one subnet reduces segmentation. A well-planned hybrid design should also include DNS, monitoring, failover testing, address planning, and security controls.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 121 Which Azure service can provide centralized connectivity and routing between multiple Azure virtual networks, branches, and remote users? Azure Virtual WAN Azure DNS Azure Bastion Azure Load Balancer Correct Answer: 1 Explanation Azure Virtual WAN provides a managed networking architecture for connecting [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18092"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18092"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18092\/revisions"}],"predecessor-version":[{"id":18093,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18092\/revisions\/18093"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18092"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}