{"id":18111,"date":"2026-09-22T05:24:27","date_gmt":"2026-09-22T05:24:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18111"},"modified":"2026-09-22T05:24:27","modified_gmt":"2026-09-22T05:24:27","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301<\/b><\/h3>\n<p><b>Which Azure Firewall feature allows DNS queries from clients to be forwarded through the firewall to configured DNS servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FastPath<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall DNS proxy can receive DNS requests from workloads and forward them to the configured DNS servers. This can help centralize DNS processing and provide more consistent name resolution for workloads that use firewall-based application rules. DNS proxy is different from DNAT, which translates destination addresses, and from FastPath or gateway transit, which address network connectivity and routing. When enabling DNS proxy, administrators should ensure that clients use the firewall as their DNS server and that the configured upstream DNS infrastructure can resolve the required public and private namespaces.<\/span><\/p>\n<h3><b>Question 302<\/b><\/h3>\n<p><b>An administrator wants to allow an NSG rule to reference several IP addresses without creating a separate rule for every address. Which capability can simplify the rule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Augmented security rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute FastPath<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NSG augmented security rules allow supported rules to include multiple IP addresses, address ranges, ports, and related criteria in a more consolidated configuration. This can reduce the number of individual rules required for common security scenarios and make administration easier. Gateway transit provides shared gateway connectivity, Traffic Manager priority controls DNS endpoint selection, and ExpressRoute FastPath improves supported network data paths. Augmented rules should still follow least-privilege principles. Administrators should avoid using broad address ranges when narrower source and destination definitions can provide the required application access.<\/span><\/p>\n<h3><b>Question 303<\/b><\/h3>\n<p><b>Which Azure service can provide a managed Layer 7 reverse proxy for web applications while supporting features such as SSL termination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Application Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Application Gateway is a managed Layer 7 application delivery service that can act as a reverse proxy for web applications. It supports features such as SSL\/TLS termination, host-based routing, path-based routing, backend health monitoring, and Web Application Firewall integration. Azure Load Balancer primarily operates at Layer 4, Route Server provides dynamic routing, and NAT Gateway manages outbound connectivity. Application Gateway should be selected when traffic decisions depend on HTTP or HTTPS information. Administrators should plan listeners, certificates, backend settings, health probes, routing rules, and security policies together.<\/span><\/p>\n<h3><b>Question 304<\/b><\/h3>\n<p><b>Which Azure VPN design can use two separate VPN gateways or connections to reduce dependency on a single connectivity path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundant VPN architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-tunnel architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted Traffic Manager architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A redundant VPN architecture uses multiple supported connectivity paths to reduce the impact of a single tunnel, gateway, device, or network failure. Depending on the design, organizations can use multiple tunnels, redundant on-premises devices, active-active gateways, or additional connections. This improves resilience when compared with relying on one connectivity path. Public DNS and Traffic Manager solve different problems and do not create VPN redundancy. Redundant designs should include appropriate routing, BGP where applicable, health monitoring, failure detection, and regular failover testing to verify that the backup path operates as expected.<\/span><\/p>\n<h3><b>Question 305<\/b><\/h3>\n<p><b>Which Azure Front Door feature allows traffic to be sent to different origins according to configured URL routes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSG priority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door route configuration determines how incoming requests are matched and forwarded to configured origins or origin groups. Routing can use domains and URL paths to direct requests toward the appropriate backend application. This allows a single Front Door profile to support multiple application routes while maintaining a global entry point. BGP peering manages network route exchange, NAT rules translate addresses, and NSG priority controls security-rule evaluation. Administrators should ensure that domains, paths, origins, forwarding protocols, caching behavior, and health monitoring are configured consistently.<\/span><\/p>\n<h3><b>Question 306<\/b><\/h3>\n<p><b>A company wants Azure Firewall to send traffic through a separate network virtual appliance for additional inspection. Which Azure routing mechanism can direct traffic toward that appliance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User-defined route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A user-defined route can specify a network virtual appliance as the next hop for traffic from a subnet. This allows administrators to create controlled traffic paths through an NVA for inspection, filtering, or other network functions. Traffic Manager provides DNS-based endpoint selection, Private DNS links associate DNS zones with virtual networks, and public IP prefixes reserve public address ranges. When routing through an appliance, administrators should verify return routes, IP forwarding, appliance configuration, and network security rules. Asymmetric routing can cause connectivity problems if both directions are not planned correctly.<\/span><\/p>\n<h3><b>Question 307<\/b><\/h3>\n<p><b>Which Azure service can connect multiple branch locations through a Microsoft-managed WAN architecture instead of requiring a full mesh of individual tunnels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN provides a managed networking architecture for connecting branches, virtual networks, VPN connections, and other supported network resources. Its virtual hubs can simplify large-scale branch connectivity by providing managed routing instead of requiring administrators to manually create a direct tunnel between every branch. Bastion provides virtual machine administration, Load Balancer distributes network traffic, and Private DNS handles name resolution. Virtual WAN planning should include hub placement, branch connectivity, routing policies, security inspection, bandwidth requirements, and the expected number of connected sites.<\/span><\/p>\n<h3><b>Question 308<\/b><\/h3>\n<p><b>Which Azure service can provide private connectivity to a supported PaaS service while allowing the service&#8217;s DNS name to resolve to a private address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint with private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager with weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix with NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route Server with BGP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address for supported Azure services, while Azure Private DNS can ensure that the service hostname resolves to that private address from appropriate virtual networks. This combination is common when organizations want applications to continue using familiar service hostnames while keeping network traffic private. Traffic Manager provides DNS-based endpoint distribution, public IP prefixes reserve public addresses, and Route Server supports dynamic routing. The DNS zone must be correctly linked and records must resolve to the intended private endpoint so applications can establish connectivity successfully.<\/span><\/p>\n<h3><b>Question 309<\/b><\/h3>\n<p><b>Which Azure networking service is designed to analyze the network topology and relationships between Azure resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Network Watcher provides network monitoring and diagnostic capabilities, including topology visualization that can help administrators understand relationships between network resources. This can be useful when investigating complex virtual networks, peering relationships, network interfaces, gateways, and other connectivity components. NAT Gateway manages outbound translation, Traffic Manager performs DNS-based traffic routing, and Firewall Manager provides centralized firewall management. Topology information can help validate whether deployed resources match the intended architecture and can reveal unexpected relationships that may contribute to routing or connectivity issues.<\/span><\/p>\n<h3><b>Question 310<\/b><\/h3>\n<p><b>Which Azure Load Balancer deployment type provides internal access to applications without requiring a public frontend IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internal Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An internal Azure Load Balancer uses a private frontend IP address and distributes traffic to backend resources within private network environments. It is appropriate for applications that should remain accessible only through internal connectivity rather than directly from the public Internet. A public Load Balancer uses a public frontend, while Traffic Manager provides DNS-based endpoint selection and Front Door provides global Layer 7 application delivery. Internal Load Balancers are commonly used for application tiers, internal services, and private architectures. Network security rules and routing should still restrict access to authorized clients.<\/span><\/p>\n<h3><b>Question 311<\/b><\/h3>\n<p><b>Which Azure VPN Gateway capability can allow supported connections to use two active gateway instances simultaneously?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-active mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multivalue routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Path-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPN Gateway active-active mode allows both gateway instances to operate simultaneously for supported configurations. This can improve resilience because connectivity does not depend exclusively on one active gateway instance. It can be particularly useful when paired with redundant on-premises VPN devices and multiple tunnels. Priority routing and multivalue routing are Traffic Manager methods, while path-based routing is associated with application-layer services such as Application Gateway. Administrators should verify compatible gateway SKUs, tunnel configuration, routing behavior, and remote-device support before deploying an active-active architecture.<\/span><\/p>\n<h3><b>Question 312<\/b><\/h3>\n<p><b>Which Azure Firewall capability can use fully qualified domain names to control outbound access for supported application traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inbound NAT rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load-balancing rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall application rules can use fully qualified domain names and application-level criteria to control supported outbound traffic. This allows administrators to create policies based on destinations such as specific web domains rather than relying solely on destination IP addresses. Inbound NAT rules translate incoming traffic, gateway transit supports shared gateway access, and load-balancing rules distribute connections among backend resources. FQDN-based rules should be carefully scoped to the domains required by applications. DNS architecture, firewall DNS proxy settings, logging, and threat intelligence should also be considered.<\/span><\/p>\n<h3><b>Question 313<\/b><\/h3>\n<p><b>Which Azure ExpressRoute feature provides a private connection between an on-premises network and supported Microsoft cloud services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ExpressRoute Microsoft peering provides private connectivity over an ExpressRoute circuit to supported Microsoft services and destinations. It allows organizations to use an ExpressRoute connection for applicable Microsoft service traffic instead of relying on public Internet connectivity. Application Gateway provides Layer 7 application delivery, Traffic Manager manages DNS-based endpoint selection, and public DNS provides public name resolution. Microsoft peering requires appropriate route advertisements and service configuration. Administrators should review the supported services, routing requirements, security controls, and circuit architecture before enabling Microsoft peering.<\/span><\/p>\n<h3><b>Question 314<\/b><\/h3>\n<p><b>Which Azure Application Gateway feature allows administrators to configure the TLS versions and cipher suites accepted by the gateway?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backend pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Health probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection draining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Gateway SSL policy controls supported TLS protocol versions and cipher suites for applicable HTTPS listeners. This allows organizations to align gateway encryption settings with security and application compatibility requirements. Backend pools identify destination servers, health probes evaluate backend availability, and connection draining supports graceful backend changes. Administrators should select an SSL policy that provides appropriate security while maintaining compatibility with legitimate clients. Changes should be tested carefully because disabling older protocols or cipher suites can prevent older clients from establishing connections.<\/span><\/p>\n<h3><b>Question 315<\/b><\/h3>\n<p><b>Which Azure networking service can provide secure connectivity from an individual user&#8217;s computer to an Azure virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Point-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Point-to-site VPN provides encrypted connectivity from an individual client device to an Azure virtual network. It is commonly used by remote users who need access to private Azure resources without connecting an entire office network. The solution can use supported authentication mechanisms and client VPN configuration. Public IP prefixes manage address ranges, Traffic Manager distributes DNS responses, and Load Balancer distributes network traffic. A point-to-site deployment should include an appropriate client address pool, authentication method, routing, DNS configuration, and NSG policies that restrict users to the resources they actually need.<\/span><\/p>\n<h3><b>Question 316<\/b><\/h3>\n<p><b>Which Azure Virtual Network Manager security rule type is designed to enforce centrally defined security requirements across selected network resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security admin rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load-balancing rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual Network Manager security administration rules provide centralized network security governance across selected virtual networks and resources. They can be used to establish organization-wide requirements that complement or govern workload-level NSG configurations. Load-balancing rules distribute network connections, DNS forwarding rules direct name-resolution queries, and DNAT rules translate destination addresses. Security administration rules should be designed with clear priorities and scopes because centralized policies can affect many workloads simultaneously. Administrators should test policy interactions carefully before applying broad security changes to production networks.<\/span><\/p>\n<h3><b>Question 317<\/b><\/h3>\n<p><b>Which Azure service is designed to provide DNS-based routing between application endpoints rather than directly proxying application traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Application Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Traffic Manager is a DNS-based traffic distribution service. It responds to DNS queries with endpoint information according to the selected routing method and endpoint health status. Unlike Application Gateway or Front Door, Traffic Manager does not act as a direct application proxy for the subsequent client connection. Application Gateway operates at Layer 7 within Azure, Front Door provides global Layer 7 delivery, and Load Balancer primarily handles Layer 4 traffic. Traffic Manager designs should consider DNS TTL values, resolver caching, endpoint monitoring, routing method, and regional application architecture.<\/span><\/p>\n<h3><b>Question 318<\/b><\/h3>\n<p><b>Which Azure networking option can provide a private frontend IP address for an Application Gateway that is intended to serve internal clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private frontend IP configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute peering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Gateway can use a private frontend IP configuration when the application should be accessed through private network connectivity. This allows internal clients to connect to the gateway without requiring a public frontend address. A public IP prefix reserves public addresses, Traffic Manager provides DNS-based endpoint selection, and ExpressRoute peering establishes private hybrid connectivity. A private Application Gateway design should include appropriate DNS records, routing, NSGs, backend configuration, and client access controls. The frontend address should be selected from the virtual network address space according to subnet and deployment requirements.<\/span><\/p>\n<h3><b>Question 319<\/b><\/h3>\n<p><b>Which Azure service can provide a managed outbound source NAT solution for an entire subnet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure NAT Gateway provides managed source network address translation for resources in an associated subnet that require outbound Internet connectivity. It allows administrators to use configured public IP addresses or a public IP prefix for predictable outbound source addressing. Bastion provides administrative access, Route Server manages BGP route exchange, and Front Door provides global application delivery. NAT Gateway is useful when external services require allowlisting of stable source addresses or when applications need scalable outbound connectivity. Inbound connectivity is not automatically created simply by associating a NAT Gateway.<\/span><\/p>\n<h3><b>Question 320<\/b><\/h3>\n<p><b>A company has two Azure regions hosting the same web application and wants users to be directed to the endpoint with the lowest network latency. Which Traffic Manager method is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multivalue<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Manager performance routing directs DNS responses toward the endpoint associated with the lowest network latency from the user&#8217;s DNS query location, based on Microsoft&#8217;s network intelligence and configured endpoints. This is useful for applications deployed across multiple regions where reducing user-to-application latency is an important requirement. Priority routing provides ordered failover, multivalue routing can return multiple healthy endpoints, and weighted routing distributes responses according to configured weights. Administrators should still configure endpoint health monitoring and consider DNS caching because clients may continue using previously resolved endpoint information.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 301 Which Azure Firewall feature allows DNS queries from clients to be forwarded through the firewall to configured DNS servers? DNS proxy DNAT FastPath Gateway transit Correct Answer: 1 Explanation Azure Firewall DNS proxy can receive DNS requests from workloads and forward them [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18111"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18111"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18111\/revisions"}],"predecessor-version":[{"id":18112,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18111\/revisions\/18112"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}