{"id":18094,"date":"2026-09-22T05:21:52","date_gmt":"2026-09-22T05:21:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18094"},"modified":"2026-09-22T05:21:52","modified_gmt":"2026-09-22T05:21:52","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>Which Azure service can provide centralized management of network security policies across multiple Azure Firewall deployments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall Manager provides centralized management capabilities for Azure Firewall policies and supported network security deployments. It can help organizations maintain consistent security configurations across multiple environments and regions. This is especially useful for enterprises that need centralized governance while operating many virtual networks or secured hubs. Azure Bastion focuses on virtual machine administration, Azure DNS provides name resolution, and Route Server supports dynamic routing. Firewall Manager should be used with clearly defined policy ownership, rule structures, administrative boundaries, monitoring, and change-management processes.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>Which Azure networking option is designed to provide private access to a supported PaaS service without sending application traffic over the public Internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-facing load balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private network interface within an Azure virtual network that connects to a supported service through Azure Private Link. Applications can communicate with the service using a private IP address instead of relying on a publicly accessible endpoint. Public IP addresses and Internet-facing load balancers expose services through public networking, while Traffic Manager provides DNS-based traffic routing. Private endpoint deployments should include appropriate DNS configuration, subnet planning, access permissions, and network security controls to ensure that applications consistently use the intended private path.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>Which Azure networking service can provide application-layer routing based on the requested URL path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Application Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Application Gateway operates at the application layer and supports URL path-based routing. This allows requests for different paths to be directed to different backend pools, making it useful for applications containing multiple services or web components. NAT Gateway provides outbound source translation, Route Server exchanges routing information through BGP, and VPN Gateway provides encrypted network connectivity. Application Gateway routing should be designed with appropriate listeners, backend pools, health probes, TLS settings, and WAF policies where application security inspection is required.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>An organization needs to connect two branch offices through Azure Virtual WAN. What component provides the centralized regional connectivity point?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual WAN hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Virtual WAN hub provides a centralized regional connectivity point for supported branch, VPN, ExpressRoute, and virtual network connections. Multiple hubs can be deployed in different regions to support geographically distributed organizations. Private DNS zones provide name resolution, Network Security Groups filter traffic, and public IP prefixes manage public address ranges. Virtual WAN hub design should consider regional placement, routing requirements, branch locations, security inspection, bandwidth, and failover. Centralized hubs can simplify large-scale connectivity compared with manually connecting every network independently.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>Which Azure networking component can automatically provide a private IP address to a private endpoint from a selected subnet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint network interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a private endpoint is created, Azure creates a network interface that receives a private IP address from the selected virtual network subnet. Applications can use this private address to communicate with the associated service through Azure Private Link. A Traffic Manager profile manages DNS-based routing, a route table defines IP forwarding behavior, and an Azure Firewall policy defines security rules. Private endpoint subnet design should account for available addresses, DNS integration, network policies, service permissions, and the number of private endpoints expected in the environment.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>Which Azure feature allows a virtual network to access a supported Azure service directly over the Azure backbone while continuing to use the service&#8217;s public endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute circuit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service endpoint extends a virtual network&#8217;s identity to supported Azure services over the Azure backbone while the service continues to use its public endpoint. This differs from a private endpoint, which provides a private IP address within the virtual network. Service endpoints can help restrict supported services so that only selected virtual networks can access them. Bastion provides administrative access, while ExpressRoute provides private connectivity to Azure through a provider. Administrators should understand the security and DNS differences between service endpoints and private endpoints before selecting either option.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>Which Azure networking capability can identify the next hop that Azure will use for traffic from a virtual machine to a specific destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher Next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS Private Resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Next hop helps administrators determine the next hop that Azure routing will select for traffic originating from a virtual machine toward a specified destination. This is useful when troubleshooting unexpected traffic paths, user-defined routes, virtual network gateways, or network virtual appliances. Front Door manages global application traffic, DNS Private Resolver handles DNS resolution, and Application Gateway provides application-layer routing. Next-hop analysis should be considered together with effective routes, NSG rules, peering configuration, gateway settings, and firewall policies when investigating connectivity problems.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>Which ExpressRoute capability can allow an organization to connect multiple on-premises locations privately through Microsoft&#8217;s network when the locations use separate ExpressRoute circuits?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute Global Reach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute Global Reach allows organizations to connect on-premises networks through their ExpressRoute circuits using Microsoft&#8217;s network. This can support scenarios where multiple locations have separate ExpressRoute connectivity and need private communication between those sites. Bastion provides virtual machine administration, Application Gateway handles web application traffic, and NAT Gateway provides outbound Internet translation. Global Reach should be evaluated alongside circuit topology, routing, bandwidth, provider arrangements, redundancy, and security requirements. Organizations should also confirm that the intended circuits and geographic architecture support the desired connectivity model.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>Which Azure networking feature can be used to apply centralized connectivity policies to a defined collection of virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual Network Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual Network Manager provides centralized management of network connectivity configurations across selected virtual networks. Administrators can organize virtual networks into network groups and apply connectivity configurations according to the organization&#8217;s topology requirements. This can simplify network governance in environments containing many subscriptions and virtual networks. Load Balancer distributes traffic, Azure DNS handles name resolution, and Bastion provides administrative access. Virtual Network Manager should be implemented with clearly defined network groups, ownership, address planning, connectivity requirements, and security boundaries.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which Azure Firewall rule type is intended to control traffic based on destination FQDNs for supported outbound application scenarios?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall application rules can control supported outbound application traffic using destination fully qualified domain names, protocols, and ports. This provides a more application-aware method of controlling Internet-bound traffic than relying only on IP-based network rules. NAT rules are used for address translation, while network rules control network-level traffic using addresses, ports, and protocols. Route rules are not an Azure Firewall policy rule category. Application rules should be scoped carefully and combined with DNS configuration, logging, monitoring, and other security controls.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>A company wants to ensure that only a specific application tier can initiate connections to a database tier. Which Azure feature can simplify the required NSG rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Security Groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Security Groups can represent application tiers within Network Security Group rules. For example, administrators can place web servers in one ASG and database servers in another, then create an NSG rule allowing the required database port only from the application-tier ASG. This avoids relying exclusively on manually maintained IP address lists. Public IP prefixes manage public addressing, NAT Gateway provides outbound translation, and Front Door provides global application delivery. ASGs are particularly useful when virtual machines are added, removed, or redeployed while retaining the same logical application role.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>Which Azure networking feature is most appropriate for providing a fixed set of public IP addresses that can be assigned to supported resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual WAN hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A public IP prefix reserves a contiguous range of public IP addresses that can be allocated to supported Azure resources. This provides predictable public addressing and can simplify address management for organizations that require several public endpoints. Network Security Groups control network traffic, private DNS zones provide internal name resolution, and Virtual WAN hubs provide centralized connectivity. Public IP prefixes should be planned according to expected resource growth and regional requirements. Organizations should avoid allocating unnecessary public addresses and should protect any publicly exposed resources with appropriate security controls.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>Which Azure networking option can provide encrypted connectivity for remote employees connecting individually from their computers to an Azure virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Site-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Point-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute Global Reach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual network peering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Point-to-site VPN provides encrypted connectivity between individual client devices and an Azure virtual network. It is commonly used for remote employees, administrators, or other users who need secure access without connecting an entire office network. Site-to-site VPN connects networks, ExpressRoute Global Reach connects supported private networks through ExpressRoute, and virtual network peering connects Azure virtual networks. Point-to-site VPN design should address authentication, client address pools, routing, authorization, supported protocols, and the specific Azure resources remote users are permitted to access.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>Which Application Gateway component receives incoming client requests and determines how those requests should be processed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Listener<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Application Gateway listener receives incoming connection requests on a configured frontend IP address, port, and protocol. Depending on the configuration, listeners can also use host names to distinguish application requests. The listener is then associated with routing rules that determine the appropriate backend behavior. Route Server manages dynamic route exchange, NAT Gateway handles outbound address translation, and DNS Resolver handles DNS queries. Application Gateway designs should ensure that listeners, frontend IPs, certificates, routing rules, backend pools, and health probes are configured consistently with application requirements.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which Azure Front Door capability allows administrators to apply configurable processing logic to requests and responses at the edge?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rules engine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSG flow rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP session<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door&#8217;s rules engine can apply configurable actions to incoming requests and responses at the edge. Depending on the supported configuration, rules can be used for tasks such as URL redirects, header modifications, and request manipulation. This can reduce the need to implement certain routing or transformation logic directly in backend applications. Route tables control IP routing, NSG rules control network traffic, and BGP sessions exchange routing information. Rules should be organized carefully to avoid conflicting actions and unexpected behavior for application users.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>Which Azure VPN Gateway deployment option can improve gateway availability by distributing gateway instances across availability zones when supported?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zone-redundant VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Gateway listener<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zone-redundant VPN Gateway deployment can improve resilience by distributing gateway infrastructure across supported availability zones within a region. This helps reduce dependence on a single availability zone and can improve connectivity resilience during zone-level failures. Public DNS zones provide Internet name resolution, Application Gateway listeners receive web requests, and Traffic Manager endpoints represent application destinations. Zone redundancy should be considered together with redundant on-premises connectivity, appropriate gateway configuration, routing, and failover testing because gateway redundancy alone does not guarantee end-to-end availability.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>Which Azure networking service is designed to continuously monitor connectivity and latency between selected source and destination endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher Connection Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Connection Monitor can continuously monitor connectivity between selected source and destination endpoints and provide information about reachability and performance. It can help administrators identify connectivity failures, latency changes, and other network problems. Firewall Manager manages firewall security policies, Private Link provides private service connectivity, and Route Server supports dynamic routing. Connection Monitor is particularly useful for validating network paths after deployment and for ongoing operational monitoring. Monitoring should include meaningful source and destination pairs that represent important application dependencies.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>Which routing behavior should an administrator understand when a custom user-defined route and a system route could both apply to the same destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Custom routing can take precedence according to Azure route selection rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS always overrides IP routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System routes are always ignored<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSGs determine the next hop<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure routing uses defined route-selection rules to determine the effective path when multiple routes could apply to a destination. User-defined routes can influence traffic forwarding and are commonly used to direct traffic toward network virtual appliances or gateways. DNS determines how names resolve to addresses but does not select the IP next hop. System routes are not universally ignored, and NSGs filter traffic rather than determine its next hop. Administrators should inspect effective routes when troubleshooting custom routing to verify which route Azure actually selected.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>Which Azure networking architecture can provide centralized hybrid connectivity while allowing separate application workloads to remain isolated in spoke networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single flat subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public-only architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent Internet gateways for every workload<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture can centralize shared connectivity services such as VPN Gateway, ExpressRoute Gateway, Azure Firewall, Bastion, and DNS components in a hub while keeping application workloads in separate spoke virtual networks. This creates logical separation and allows organizations to apply centralized security and routing policies. A flat subnet provides less isolation, while independent Internet gateways can make centralized governance more difficult. Hub-and-spoke designs should include appropriate peering, route propagation, UDRs, security rules, DNS architecture, and redundancy requirements.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>A network administrator needs to verify whether a specific TCP connection is allowed or denied by the effective NSG configuration before changing production rules. Which tool is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher IP flow verify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS Private Resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher IP flow verify can evaluate whether traffic between a specified source and destination, using a particular protocol and port, is allowed or denied by the effective network security configuration. It is useful for troubleshooting NSG behavior without immediately modifying production rules. Traffic Manager performs DNS-based application routing, Front Door provides global application delivery, and DNS Private Resolver handles DNS resolution. IP flow verification should be combined with effective security rules and effective routes when diagnosing complex connectivity problems.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 141 Which Azure service can provide centralized management of network security policies across multiple Azure Firewall deployments? Azure Bastion Azure Firewall Manager Azure DNS Azure Route Server Correct Answer: 2 Explanation Azure Firewall Manager provides centralized management capabilities for Azure Firewall policies and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18094"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18094"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18094\/revisions"}],"predecessor-version":[{"id":18095,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18094\/revisions\/18095"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}