{"id":18103,"date":"2026-09-22T05:23:16","date_gmt":"2026-09-22T05:23:16","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18103"},"modified":"2026-09-22T05:23:16","modified_gmt":"2026-09-22T05:23:16","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which Azure Traffic Manager routing method directs users to an endpoint based on a configured priority order?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multivalue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Manager priority routing allows administrators to define an ordered list of endpoints. Traffic Manager directs DNS queries toward the highest-priority available endpoint and uses lower-priority endpoints when higher-priority endpoints are unavailable. This method is useful when one endpoint should normally serve traffic while another acts as a failover destination. Weighted routing distributes traffic according to assigned weights, geographic routing considers user location, and multivalue routing can return multiple healthy endpoints. Health monitoring should be configured so unavailable endpoints are removed from consideration.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>An organization needs to inspect encrypted HTTPS traffic at the Azure firewall before allowing it to reach internal workloads. Which Azure Firewall Premium capability is designed for this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall Premium provides TLS inspection capabilities that can decrypt and inspect supported encrypted traffic before re-encrypting it toward the destination. This can provide deeper visibility into HTTPS traffic and support security inspection policies that cannot be applied when traffic remains encrypted. DNAT performs destination address translation, peering connects virtual networks, and load balancing distributes traffic across backend resources. TLS inspection requires appropriate certificate deployment and careful planning because certificate trust, privacy, performance, application compatibility, and security policy requirements must all be considered.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which Azure ExpressRoute feature allows private connectivity between virtual networks that are connected through different ExpressRoute circuits?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FastPath<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute Global Reach allows private connectivity between on-premises networks connected to different ExpressRoute circuits. It can help organizations connect geographically distributed corporate locations through Microsoft&#8217;s private network infrastructure rather than relying entirely on the public Internet. FastPath is designed to improve data-path performance by allowing traffic to bypass certain gateway processing, while NAT Gateway and Private DNS serve different purposes. Global Reach planning should consider circuit locations, peering configuration, routing advertisements, supported scenarios, and the organization&#8217;s existing hybrid network topology.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>A company wants Azure Firewall to resolve domain names through a designated DNS server instead of relying only on default DNS resolution. Which feature can support this design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall DNS proxy can allow DNS requests from protected workloads to be processed through the firewall and forwarded according to the configured DNS architecture. This can provide centralized DNS visibility and help maintain consistent name resolution for firewall application rules that depend on fully qualified domain names. Public IP prefixes manage address ranges, gateway transit enables gateway sharing across peered networks, and connection draining is an Application Gateway capability. DNS proxy should be designed together with the organization&#8217;s private zones, DNS servers, forwarding requirements, and firewall policies.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>Which Application Gateway feature allows multiple websites with different host names to share the same Application Gateway instance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multi-site listener<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Health probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backend pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Gateway multi-site listeners allow a single Application Gateway to support multiple websites by matching incoming requests according to host names. This can reduce the need for separate gateways when several web applications can share the same entry point and security architecture. Backend pools contain the destination servers, health probes monitor backend availability, and connection draining helps existing connections complete during backend changes. Multi-site designs should use appropriate DNS records, listener configuration, certificates, routing rules, and backend settings to ensure each hostname reaches the intended application.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which Azure Virtual WAN capability can automatically provide connectivity between branches connected to the same virtual hub?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Branch-to-branch connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS linking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN supports branch-to-branch connectivity through its managed virtual hub architecture. Branch sites connected to Virtual WAN can communicate through the Microsoft-managed WAN infrastructure without requiring every branch to maintain direct tunnels to every other branch. This simplifies large distributed network designs and can reduce the operational complexity of full-mesh connectivity. Public IP prefixes manage address ranges, service endpoints provide optimized Azure service access, and Private DNS links provide name resolution. Routing policies, security inspection, hub configuration, and connectivity requirements should still be planned carefully.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which Azure Application Gateway setting determines how a gateway communicates with servers in a backend pool, including protocol and port information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSG priority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Gateway HTTP settings define important communication parameters between the gateway and backend servers. Depending on the configuration, these settings can specify the backend protocol and port, host name behavior, connection draining, cookie-based affinity, and related options. Backend pools identify the servers that can receive requests, while route tables and NSG priorities perform different network functions. Correct HTTP settings are important when backend applications use nonstandard ports, HTTPS, specific host headers, or session requirements. Misconfigured settings can cause gateway-generated backend connection failures.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which Azure networking service is primarily responsible for distributing incoming network traffic across multiple backend resources at Layer 4?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS Private Resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Load Balancer operates primarily at Layer 4 and distributes TCP or UDP traffic across healthy backend resources. It uses frontend IP configurations, load-balancing rules, backend pools, and health probes to determine how connections are handled. Azure Front Door provides global Layer 7 application delivery, DNS Private Resolver handles DNS resolution, and Firewall Manager provides centralized firewall management capabilities. Load Balancer designs should account for frontend configuration, backend health, availability zones where applicable, inbound NAT requirements, and whether internal or public exposure is appropriate.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>A network administrator needs to determine which route Azure will use to reach a particular destination from a virtual machine. Which Network Watcher capability is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP flow verify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Topology<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Next hop determines the next hop for traffic originating from a virtual machine toward a specified destination. It can help administrators understand whether traffic will use a virtual network route, Internet route, virtual appliance, or another applicable next hop. IP flow verify focuses on security-rule decisions, Packet Capture records traffic for analysis, and Topology provides a network-resource view. Next hop is particularly useful when troubleshooting unexpected routing caused by system routes, user-defined routes, peering, or network virtual appliances.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>Which Azure networking option provides a private connection from an Azure virtual network to a supported PaaS service without exposing the service through a public IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint creates a private IP address inside an Azure virtual network and maps that endpoint to a supported Azure service through Azure Private Link. This allows applications to reach the service using private connectivity rather than a publicly accessible service endpoint. Service endpoints provide a different security and routing model in which traffic remains on the Azure backbone while the service still uses its public endpoint. Traffic Manager manages DNS-based distribution, and public IP prefixes reserve public addresses. Private endpoint deployments should include appropriate DNS configuration and network access controls.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which ExpressRoute capability can improve data-path performance by allowing supported traffic to bypass the ExpressRoute virtual network gateway?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FastPath<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute FastPath is designed to improve network performance for supported traffic by providing a more direct data path between on-premises networks and virtual network resources. This can reduce the amount of gateway processing involved in the data path and may improve latency and throughput for appropriate workloads. Global Reach connects on-premises networks through ExpressRoute, gateway transit supports shared gateway scenarios, and DNS proxy handles DNS forwarding through Azure Firewall. FastPath has specific support and design considerations, so administrators should verify compatibility before deployment.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>Which Azure VPN Gateway capability can allow two gateway instances to operate simultaneously to improve availability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-active mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPN Gateway active-active mode allows both gateway instances to operate simultaneously, providing a more resilient VPN architecture than relying on a single active instance. Connections can be established across the available gateway instances according to the supported configuration. Priority and weighted routing are Traffic Manager concepts, while connection draining is associated with Application Gateway backend changes. Active-active VPN designs require compatible configuration on the on-premises side and should account for tunnel setup, BGP where applicable, redundant devices, monitoring, and failure scenarios.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which Azure feature allows an administrator to restrict access to a storage account from selected virtual networks while using service endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage firewall and virtual network rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Gateway listener<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Storage supports network access controls that can restrict service access to selected virtual networks and subnets when the appropriate service endpoint architecture is used. This allows administrators to limit which network locations can access the storage service while retaining the service&#8217;s supported endpoint model. Traffic Manager priority routing manages DNS traffic distribution, Application Gateway listeners accept web requests, and public IP prefixes reserve public addresses. Storage network restrictions should be combined with identity-based authorization, appropriate firewall settings, and carefully selected subnet access to create layered protection.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which Azure Bastion capability allows administrators to connect to virtual machines without assigning public IP addresses directly to those virtual machines?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser-based RDP\/SSH through Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP route advertisement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Layer 4 load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Bastion provides managed RDP and SSH connectivity to virtual machines through the Azure portal without requiring public IP addresses on those virtual machines. This can reduce direct Internet exposure of management interfaces while providing controlled administrative access through the Bastion service. BGP route advertisement is associated with dynamic routing, DNS forwarding handles name resolution, and Layer 4 load balancing distributes network traffic. Bastion deployments should still use appropriate identity controls, network security rules, subnet configuration, and administrative procedures to protect management access.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>Which Traffic Manager routing method can return multiple healthy endpoints in response to a DNS query?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multivalue<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Manager multivalue routing can return multiple healthy endpoint addresses in DNS responses. This can provide clients with several possible destinations and can support application designs where multiple endpoints should remain available rather than selecting only one destination. Priority routing focuses on ordered failover, geographic routing considers the client&#8217;s location, and weighted routing distributes DNS responses according to configured weights. Multivalue routing should be evaluated alongside endpoint health monitoring, client DNS behavior, application retry behavior, and the number of endpoints that should be returned.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>An organization wants to make one Azure Firewall policy inherit common rules from a centrally managed parent policy. Which capability supports this arrangement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy inheritance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall policy inheritance allows child policies to inherit configurations from a parent policy in supported hierarchical designs. This can help central teams define common security controls while allowing more specific policies to address individual environments. Gateway transit is a network peering capability, NAT translation changes network addresses, and connection monitoring evaluates connectivity. Policy hierarchy should be planned carefully so that centrally managed rules remain consistent while delegated administrators have appropriate control. Administrators should understand rule collection processing and inheritance behavior before deploying complex policy structures.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which Application Gateway feature can maintain a user&#8217;s session with the same backend server by using an application gateway-generated cookie?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cookie-based affinity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Gateway cookie-based affinity can help maintain session persistence by directing subsequent requests from a client to the same backend server when supported by the configuration. This can be useful for applications that maintain session state locally rather than storing it in a shared session repository. BGP peering handles route exchange, public IP prefixes manage public address ranges, and DNS forwarding handles name resolution. Session affinity should not automatically replace application-level session design because backend failures and scaling events can still affect session continuity.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>Which Azure networking architecture is most appropriate when Internet-bound traffic from multiple spoke networks must pass through a centralized security appliance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Direct spoke-to-Internet connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke with forced routing through an NVA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent public IP allocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate DNS zones only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture can centralize security inspection by routing Internet-bound traffic from spoke networks through a network virtual appliance or Azure Firewall in the hub. User-defined routes can direct the required traffic toward the inspection device, while return paths must be designed to preserve routing symmetry. Direct spoke-to-Internet connectivity does not provide centralized inspection, public IP allocation alone does not establish a security path, and DNS zones do not control network traffic forwarding. The design should consider high availability, routing, firewall policies, monitoring, and failure behavior.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which Azure Virtual WAN capability can be used to steer traffic through security services based on centralized routing policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing intent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN routing intent allows administrators to define routing policies that steer traffic through designated security solutions in supported virtual hub architectures. This can help create centralized security inspection for traffic such as Internet-bound or private network traffic while reducing the need for extensive manual route management. Public IP prefixes manage address ranges, service endpoints provide Azure service connectivity, and private DNS links control DNS zone association. Routing intent should be planned alongside secured virtual hub architecture, firewall deployment, route propagation, branch connectivity, and required traffic inspection paths.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>A network team is choosing between Azure Application Gateway and Azure Load Balancer for a web application that requires URL-based routing. Which requirement points specifically toward Application Gateway?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UDP load distribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL path-based routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic TCP forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network-level health probing only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URL path-based routing is an Application Gateway capability designed for Layer 7 web traffic. It allows requests to different URL paths to be directed toward different backend pools or application services. Azure Load Balancer primarily operates at Layer 4 and is better suited to TCP or UDP traffic distribution without understanding HTTP URL paths. Choosing between the services should consider application-layer requirements, protocol support, TLS handling, security controls, health monitoring, scalability, and network architecture. The requirement to inspect and route requests based on HTTP content strongly favors an application delivery service.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 221 Which Azure Traffic Manager routing method directs users to an endpoint based on a configured priority order? Priority Weighted Geographic Multivalue Correct Answer: 1 Explanation Traffic Manager priority routing allows administrators to define an ordered list of endpoints. Traffic Manager directs DNS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18103"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18103"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18103\/revisions"}],"predecessor-version":[{"id":18104,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18103\/revisions\/18104"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}