{"id":18105,"date":"2026-09-22T05:23:32","date_gmt":"2026-09-22T05:23:32","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18105"},"modified":"2026-09-22T05:23:32","modified_gmt":"2026-09-22T05:23:32","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which Azure Firewall capability can identify and block known malicious traffic based on threat intelligence information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall threat intelligence filtering can identify traffic associated with known malicious IP addresses and domains and apply configured actions such as alerting or denial. This provides an additional security layer beyond manually created firewall rules. DNAT performs destination network address translation, gateway transit supports shared gateway connectivity, and connection draining is an Application Gateway feature. Threat intelligence should be used alongside carefully designed network and application rules, logging, monitoring, and other security controls because threat intelligence alone does not address every possible attack or unauthorized communication path.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Which Azure VPN Gateway setting can be used when an organization requires a specific combination of IPsec and IKE cryptographic parameters?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Custom IPsec\/IKE policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A custom IPsec\/IKE policy allows supported Azure VPN Gateway configurations to specify particular cryptographic parameters for IPsec and IKE negotiations. This can be important when connecting Azure to an on-premises VPN device that requires specific encryption, integrity, Diffie-Hellman, or related settings. Traffic Manager manages DNS-based traffic routing, service endpoint policies apply to supported Azure services, and DNS forwarding rules control name-resolution forwarding. Before applying a custom policy, administrators should verify that the settings are compatible with the remote VPN device and the selected gateway configuration.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which ExpressRoute peering type is intended for private connectivity between an on-premises network and Azure virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet peering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute private peering provides private connectivity between an on-premises network and Azure virtual networks through an ExpressRoute circuit. It is commonly used for hybrid workloads that require private network communication without traversing the public Internet. Microsoft peering is designed for supported Microsoft services and destinations rather than direct virtual network connectivity. Public peering is a historical ExpressRoute concept and is not the standard choice for current Azure virtual network connectivity. Private peering requires appropriate circuit, gateway, VLAN, IP addressing, and routing configuration.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>An administrator needs to allow several virtual machines to communicate with an application tier while avoiding hard-coded individual VM IP addresses in NSG rules. Which approach is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Security Groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefixes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Security Groups allow network interfaces to be grouped according to application roles and referenced directly by Network Security Group rules. This makes security policies easier to maintain when workload instances change over time. Instead of continually updating rules with individual IP addresses, administrators can define communication between logical groups such as web, application, and database tiers. Public IP prefixes manage public address ranges, Traffic Manager distributes DNS-based traffic, and Azure DNS provides name resolution. ASGs should still be combined with specific ports, protocols, and least-privilege access requirements.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which Azure Front Door capability allows an administrator to keep an origin&#8217;s hostname separate from the hostname used by clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Origin host header<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSG priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door can use an origin host header to control the hostname presented to the backend origin when Front Door forwards a client request. This is useful when the public hostname used by clients differs from the hostname expected by the origin application or web server. NSG priority controls the order of security rules, BGP routes support dynamic routing, and NAT rules translate network addresses. Origin host header configuration should match the backend application&#8217;s expectations, TLS certificate requirements, and host-based routing behavior to prevent unexpected backend errors.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which Azure service is designed to provide secure browser-based administrative access to virtual machines through RDP and SSH without exposing those management ports directly to the Internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Bastion provides managed administrative access to Azure virtual machines through RDP and SSH from the Azure portal without requiring public IP addresses on the individual virtual machines. This can reduce direct exposure of management ports to the Internet. Traffic Manager provides DNS-based application routing, Route Server supports BGP route exchange, and NAT Gateway provides managed outbound connectivity. Bastion should be deployed with appropriate subnet configuration and strong identity controls. Network security rules should also restrict unnecessary access to management resources and supporting network components.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which Traffic Manager routing method is useful when different endpoints should serve users based on their geographic location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multivalue<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Manager geographic routing directs DNS responses according to the geographic location associated with the DNS query. It can be useful when an organization wants users from different regions to reach different application endpoints because of regulatory, localization, performance, or architectural requirements. Priority routing is intended for ordered failover, multivalue can return multiple healthy endpoints, and weighted routing distributes responses according to configured weights. Geographic routing requires careful mapping of geographic regions to endpoints and should be evaluated alongside endpoint health monitoring and DNS caching behavior.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which Azure Load Balancer capability can forward a specific inbound port from a frontend IP address to a specific virtual machine instance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inbound NAT rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP session<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Load Balancer inbound NAT rules can map a frontend IP address and port to a specific backend virtual machine and port. This can be useful for scenarios such as accessing individual virtual machines for administration or testing through a load balancer frontend. Application rules are associated with Azure Firewall, DNS forwarding rules manage name resolution, and BGP sessions exchange routing information. Inbound NAT should be used carefully because it can create externally reachable management or application ports. Appropriate network security controls and restricted source access remain important.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which Azure Private DNS configuration allows virtual networks to resolve records from a private DNS zone?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual network link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route Server peer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load-balancing rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual network link associates a private DNS zone with a virtual network, allowing resources in that network to resolve records contained in the zone. This is a fundamental component of private name resolution for internal applications and many private endpoint deployments. Public IP prefixes manage public address ranges, Route Server peers exchange routes, and load-balancing rules distribute traffic. Administrators should verify that the correct virtual networks are linked and that DNS clients use the expected Azure-provided or custom DNS infrastructure. Incorrect zone links can result in name-resolution failures despite healthy network connectivity.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which Azure networking architecture is commonly used to centralize shared services such as firewalls, DNS, and hybrid connectivity while keeping application networks separate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full public exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single flat subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent Internet routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture places shared networking services in a central hub while application workloads are deployed in separate spoke virtual networks. The hub can contain services such as Azure Firewall, VPN or ExpressRoute gateways, DNS components, and other shared infrastructure. Spokes can remain logically separated while using approved connectivity through the hub. This model can improve centralized governance and simplify hybrid connectivity, although routing, security boundaries, address spaces, and availability must be planned carefully. It is particularly useful for organizations managing multiple application environments or business units.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which Azure service can provide Layer 7 web application protection against common HTTP-based attacks when integrated with an Application Gateway?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Application Firewall provides Layer 7 protection for supported HTTP and HTTPS applications and can be integrated with Application Gateway. It can help protect applications against common web attacks by inspecting HTTP requests and applying configured security rules. Route Server handles dynamic routing, NAT Gateway manages outbound source translation, and public IP prefixes reserve public address ranges. WAF policies should be tuned according to application requirements because overly restrictive rules can block legitimate requests. Monitoring logs and reviewing detected events are important for maintaining effective application-layer protection.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which Azure Virtual Network Manager configuration is designed to connect all virtual networks within a defined network group to each other?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mesh connectivity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual Network Manager mesh connectivity can establish connectivity among virtual networks that belong to the applicable network group. This can simplify large-scale connectivity management when multiple networks need direct communication without individually configuring every peering relationship. Priority routing belongs to Traffic Manager, DNAT is a firewall address-translation function, and DNS forwarding handles name-resolution requests. Network Manager configurations should be scoped carefully because mesh connectivity can create broader communication paths than a strictly hub-and-spoke model. Administrators should define network groups according to actual application and security requirements.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>A company wants clients to reach an application through a single global endpoint while Azure automatically directs requests toward healthy regional origins. Which service is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS Private Resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door provides a global entry point for HTTP and HTTPS applications and can route requests toward configured origins based on health and routing configuration. It is designed for global application delivery and can help organizations provide a consistent public endpoint while distributing traffic across regional application deployments. Route Server provides dynamic routing, NAT Gateway manages outbound connectivity, and DNS Private Resolver handles private DNS resolution. Front Door architectures should include origin health configuration, routing rules, TLS requirements, caching decisions, and appropriate protection for the backend origins.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which Azure networking feature can prevent traffic from a private endpoint subnet from being subject to certain network policies when those policies are not supported for the deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint network policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute FastPath<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private endpoint network policies control whether certain network policies can be applied to private endpoints within a subnet. Administrators can configure the relevant subnet behavior according to supported private endpoint scenarios and required network controls. Traffic Manager priority determines DNS endpoint failover order, public IP prefixes reserve public addresses, and ExpressRoute FastPath relates to optimized ExpressRoute data paths. Private endpoint subnet configuration should be planned before deployment because network policy behavior can affect security inspection, routing, and traffic management. Always verify supported policy combinations for the specific Azure networking architecture.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which Azure VPN Gateway feature can improve availability by deploying the gateway across availability zones in supported regions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zone-redundant gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multivalue DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Security Group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zone-redundant VPN Gateway can provide improved resilience by distributing gateway infrastructure across availability zones in supported Azure regions. This reduces dependence on a single availability zone and can help maintain VPN connectivity during certain zone-level failures. Weighted routing is a Traffic Manager method, multivalue DNS is unrelated to VPN gateway infrastructure, and Application Security Groups organize network interfaces for NSG rules. Zone-redundant gateway selection should be considered alongside redundant tunnels, on-premises device redundancy, appropriate gateway SKUs, routing design, and tested recovery procedures.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which Azure Firewall feature allows administrators to perform URL filtering for supported web traffic using application-level rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inbound NAT rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route tables<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall application rules provide application-layer filtering for supported web protocols and can use fully qualified domain names and other application-aware criteria. This enables administrators to create policies that control access to approved destinations rather than relying only on IP addresses and ports. Inbound NAT rules perform destination translation, route tables determine network paths, and gateway transit enables use of a shared gateway across peered networks. Application rules should follow least-privilege principles and be combined with network rules, threat intelligence, logging, and monitoring where appropriate.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which ExpressRoute feature is designed to allow supported traffic to take a more direct path instead of being processed through the virtual network gateway data path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FastPath<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reach<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute FastPath is designed to provide a more direct data path for supported traffic between an on-premises network and Azure virtual network resources. By reducing dependency on certain gateway data-path processing, FastPath can improve network performance for applicable workloads. Global Reach provides private connectivity between on-premises networks through ExpressRoute, Private DNS provides internal name resolution, and service endpoints provide optimized access to supported Azure services. FastPath has specific prerequisites and limitations, so organizations should verify the selected gateway, resource types, and architecture before relying on it for performance improvements.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which Azure service can centrally manage security policies across Azure Firewall deployments in multiple virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall Manager provides centralized management capabilities for Azure Firewall deployments and security policies across supported network environments. It can help organizations apply consistent security governance while managing multiple firewalls and network architectures. Traffic Manager manages DNS-based traffic distribution, Bastion provides secure administrative access, and Azure DNS provides name-resolution services. Centralized firewall management is particularly useful in larger environments where separate teams or subscriptions contain multiple network segments. Administrators should establish clear policy ownership, hierarchy, delegated administration, logging, and change-management procedures.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which Azure service is appropriate when a workload requires outbound Internet access but should use a predictable public source IP address without assigning a public IP directly to each virtual machine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure NAT Gateway provides managed outbound Internet connectivity for resources in an associated subnet while using configured public IP addresses for source network address translation. This allows workloads to communicate externally without assigning public IP addresses directly to each virtual machine. It can also provide predictable outbound source addresses for allowlisting by external services. Front Door provides global application delivery, Route Server handles dynamic routing, and Private DNS provides private name resolution. NAT Gateway should be deployed with appropriate subnet design and security controls to ensure only intended workloads receive outbound connectivity.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>A company needs to connect Azure workloads privately to an on-premises network and requires predictable network performance without sending traffic through the public Internet. Which option is designed for this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute provides private connectivity between an organization&#8217;s network and Microsoft cloud services through an ExpressRoute circuit rather than using the public Internet for the primary connection. It is suitable for workloads requiring predictable connectivity characteristics, private routing, and enterprise hybrid-network integration. Traffic Manager provides DNS-based endpoint selection, Front Door provides global HTTP and HTTPS delivery, and public IP prefixes reserve public addresses. ExpressRoute planning should include circuit location, provider availability, private peering, gateway sizing, routing requirements, redundancy, and appropriate failover arrangements for business-critical workloads.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which Azure Firewall capability can identify and block known malicious traffic based on threat intelligence information? DNAT Threat intelligence Gateway transit Connection draining Correct Answer: 2 Explanation Azure Firewall threat intelligence filtering can identify traffic associated with known malicious IP addresses and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18105"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18105"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18105\/revisions"}],"predecessor-version":[{"id":18106,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18105\/revisions\/18106"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}