{"id":18119,"date":"2026-09-22T05:25:45","date_gmt":"2026-09-22T05:25:45","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18119"},"modified":"2026-09-22T05:25:45","modified_gmt":"2026-09-22T05:25:45","slug":"microsoft-az-700-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-700-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Microsoft AZ-700 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-700-exam-dumps\"><b>Microsoft AZ-700 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>An organization wants to use Azure Firewall Manager to centrally deploy and manage third-party security solutions across Azure virtual hubs. Which capability should the organization use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint network policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security partner provider<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager multivalue routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall Manager can integrate supported third-party security providers with secured virtual hubs. A security partner provider allows organizations to use a supported network virtual appliance or security service for centralized traffic inspection within the Virtual WAN architecture. This approach can help enterprises standardize security enforcement across multiple regional hubs instead of deploying independent inspection solutions in every network. The selected provider must support the relevant Azure integration and routing architecture. Administrators should also plan how traffic is forwarded through the security service and how security policies are centrally maintained.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>A Load Balancer is being used to expose a service that requires connections from clients to be redirected to specific backend virtual machines. The administrator wants to translate an incoming frontend port to a different backend port for a particular VM. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Health probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inbound NAT rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Outbound rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backend pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An inbound NAT rule on Azure Load Balancer can map an incoming connection on a frontend IP and port to a specific backend virtual machine and port. This is useful when administrators need direct access to an individual VM through the load balancer&#8217;s frontend configuration rather than distributing the request across a backend pool. The rule defines the frontend and backend port mapping and identifies the target backend instance. Inbound NAT rules are commonly useful for administrative or application-specific access scenarios where a direct translation to a particular backend resource is required.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>A company wants an Azure Load Balancer deployment to continue providing connectivity if an availability zone becomes unavailable. Which frontend configuration should the administrator consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zone-redundant frontend IP configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager priority profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zone-redundant frontend IP configuration allows an Azure Load Balancer frontend to provide greater resilience across availability zones. Instead of associating the frontend with only one zone, a zone-redundant configuration can remain available when an individual availability zone experiences an outage. This is useful for applications that require high availability at the regional level. The backend architecture must also be designed appropriately so that workloads are distributed across suitable zones or otherwise remain available during failures. Administrators should evaluate both frontend and backend resiliency rather than relying on a single redundancy feature.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>A company uses an Azure Storage account and wants to restrict access through a service endpoint so that only selected subnets can reach the account. Which additional feature can provide more granular control over supported service endpoint traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Front Door origin group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service endpoint policies provide additional control over access to supported Azure services when traffic originates from virtual network subnets using service endpoints. They can help administrators restrict which resources within a supported Azure service can be accessed through the configured endpoint. This provides more granular control than simply enabling a service endpoint on a subnet. Service endpoint policies are particularly useful when organizations want to reduce unintended access to resources while continuing to use service endpoint connectivity. Administrators should verify service support and configure the policy according to the required resource scope.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Two VNets are peered, and workloads in one VNet must send traffic through a network virtual appliance located in the other VNet. Which peering option is important for allowing the forwarded traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow forwarded traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use remote gateways<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow gateway transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable service endpoints<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Allow forwarded traffic peering option permits traffic that is forwarded through a network virtual appliance or other intermediary to traverse the peering connection. This is important when one VNet contains a firewall, router, or network virtual appliance that processes traffic originating from another VNet. Without the appropriate peering configuration, traffic that has been forwarded through an intermediary may not be accepted across the peering relationship. Administrators should configure the corresponding route tables and security controls as well, because enabling forwarded traffic alone does not create the required routing path.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>An organization wants to protect its public-facing Azure resources against volumetric network attacks by using a centrally managed DDoS protection plan. Which Azure capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS Private Resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Route Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection provides dedicated protection capabilities for resources with public IP addresses against distributed denial-of-service attacks. A DDoS protection plan can be associated with supported virtual networks so that protected resources receive enhanced mitigation capabilities compared with basic platform-level protection. This is useful for organizations operating public-facing applications where network-layer attacks could affect availability. DDoS protection complements other security controls such as network security groups, Azure Firewall, and web application firewalls. Administrators should identify the public-facing resources requiring protection and incorporate DDoS controls into the overall network security architecture.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>An enterprise wants Front Door to connect privately to an origin instead of exposing the origin application directly to the public Internet. Which capability can support this architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Front Door Private Link origin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager multivalue routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Front Door can use Private Link for supported origins, allowing traffic between Front Door and the origin to use a private connection rather than requiring the origin to be directly exposed to public Internet traffic. This architecture can reduce the public exposure of backend applications while still allowing Front Door to provide global application delivery. The origin must be configured to support the required Private Link integration, and the private endpoint connection generally requires appropriate approval. Administrators should also configure DNS, origin settings, and access controls correctly so that the backend accepts traffic only through the intended architecture.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>An Application Gateway backend application uses a certificate issued by a private certification authority. The gateway must trust that certificate when establishing HTTPS connections to the backend. What should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted root certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When Application Gateway establishes HTTPS connections to backend servers, it may need to trust certificates issued by a private or internal certification authority. A trusted root certificate can be configured for the relevant backend HTTP settings so that Application Gateway can validate the backend server certificate. This is particularly useful in enterprise environments where internal applications use certificates issued by a private PKI. The certificate chain and backend configuration must be correct, and the certificate should correspond appropriately to the backend connection. This helps maintain encrypted communication while allowing proper certificate validation.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>A company wants Traffic Manager to route users according to the source IP address ranges they originate from. Different geographic IP ranges should receive traffic from different application endpoints. Which routing method should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subnet routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic Manager subnet routing allows administrators to associate client IP address ranges with specific endpoints. When a DNS request is received, Traffic Manager evaluates the source address and can return the endpoint associated with the configured subnet mapping. This is useful when organizations need explicit control over which endpoint serves clients from particular network ranges. It can support scenarios such as directing corporate networks to dedicated application instances while sending other clients elsewhere. Subnet routing differs from performance routing, which uses network latency measurements, and priority routing, which primarily supports ordered failover.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>A network team needs to reduce the risk of a VPN gateway becoming unavailable because of a failure affecting a single availability zone. Which gateway architecture should be selected when supported?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zone-redundant VPN gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-zone gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zone-redundant VPN gateway is designed to improve resilience by distributing gateway instances across availability zones within a supported Azure region. This helps reduce the impact of a failure affecting a single zone. Zone redundancy is particularly valuable for hybrid environments where VPN connectivity is important to business operations. The chosen gateway SKU and regional availability must support the required architecture. Administrators should also consider redundant on-premises devices, multiple tunnels, appropriate routing, and independent connectivity paths because gateway zone redundancy alone does not eliminate every possible source of hybrid network failure.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>A company wants to prevent accidental access to an Azure Storage account from unauthorized VNets while still using private endpoints for approved workloads. Which design provides the strongest network isolation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expose the storage account through a public IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use a private endpoint and restrict public network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use Traffic Manager with priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use a public Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address within the organization&#8217;s virtual network for supported Azure services such as Storage. Restricting public network access in combination with a private endpoint can significantly reduce the service&#8217;s public exposure and force approved workloads toward the intended private connectivity path. Private DNS integration can also ensure that the service hostname resolves to the private endpoint from authorized networks. Administrators should verify that all required clients can resolve and route to the private address. This architecture is useful when minimizing Internet exposure is a primary security requirement.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>An administrator needs to connect an Azure virtual network to an on-premises environment and wants dynamic route exchange instead of maintaining static routes manually. Which protocol is commonly used with Azure VPN Gateway for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Border Gateway Protocol, or BGP, enables dynamic exchange of network routes between supported Azure VPN Gateway configurations and on-premises network devices. Instead of manually defining every route, BGP can advertise and learn prefixes dynamically as network topology changes. This is useful in larger hybrid environments where multiple networks, redundant tunnels, or changing routes are involved. The on-premises VPN devices must support compatible BGP configuration, and administrators need to plan autonomous system numbers, peer addresses, and advertised prefixes. Proper route filtering is also important so that only intended network ranges are exchanged.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>An organization wants to ensure that Azure resources in a subnet use a predictable public source address when making outbound Internet connections. Which architecture should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Link service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher topology<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NAT Gateway provides centralized and predictable outbound Internet connectivity for resources deployed in an associated subnet. Outbound connections can use the public IP addresses configured on the NAT Gateway, giving organizations stable source addresses that can be allowlisted by external services. This avoids assigning public IP addresses directly to every virtual machine and can simplify outbound network management. NAT Gateway also provides scalable SNAT capacity for high-volume outbound workloads. Administrators should associate it with the appropriate subnet and ensure that routing and public IP configuration match the application&#8217;s connectivity requirements.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>A network engineer wants to identify the Azure network topology, including VNets, subnets, peering relationships, and connected resources, from a centralized diagnostic service. Which Network Watcher capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection troubleshoot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Topology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP flow verify<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Topology provides a visual representation of network resources and their relationships within an Azure environment. It can help administrators understand how virtual networks, subnets, network interfaces, peerings, and other supported resources are connected. This is useful when troubleshooting complex architectures or reviewing whether the deployed topology matches the intended design. Topology is different from packet capture, which collects network traffic, and IP flow verify, which evaluates whether traffic is permitted or denied. Using topology information can help engineers identify missing relationships or unexpected network configurations before performing deeper diagnostics.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>A company wants Azure Firewall to perform domain name resolution for application rules instead of allowing workloads to resolve every external domain independently. Which Azure Firewall capability should be enabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inbound NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP prefix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall DNS proxy allows DNS queries from protected workloads to be processed through the firewall. When DNS proxy is enabled and clients are configured appropriately, the firewall can resolve domain names and use the resulting information when applying relevant application and network policies. This can provide greater consistency between DNS resolution and firewall filtering decisions. It is particularly useful when application rules depend on fully qualified domain names. Administrators should configure the appropriate DNS settings and ensure that clients send their queries through the intended DNS path rather than bypassing the firewall&#8217;s configured resolution architecture.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>An administrator needs to determine which route Azure would select for traffic from a virtual machine toward a specific destination IP address. Which Network Watcher capability provides this information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP flow verify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Next Hop determines the next hop Azure would use for traffic from a virtual machine toward a specified destination. It can help administrators understand whether traffic will use a virtual network gateway, virtual appliance, Internet route, or another applicable next hop. This is especially useful when custom route tables, system routes, peering, or network virtual appliances are involved. IP flow verify focuses on security-rule evaluation rather than route selection, while packet capture collects actual traffic. Next Hop is therefore appropriate when the primary question concerns the routing decision for a particular destination.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>A company needs to connect several branch offices to Azure through a centralized WAN architecture and wants Microsoft-managed connectivity between branches and Azure regions. Which service is designed for this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Virtual WAN provides a managed networking architecture for connecting branches, VNets, remote users, and other network resources through Microsoft-managed virtual hubs. It is designed to simplify large-scale WAN connectivity and reduce the need to manually build complex point-to-point network relationships. Branch connectivity can use supported VPN or other connectivity options, while virtual hubs provide centralized routing. Organizations can also integrate security services and configure routing policies according to their requirements. Virtual WAN is particularly useful for enterprises with geographically distributed locations that need a scalable and centrally managed connectivity framework.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>An organization wants to reduce the number of individual VNet peering relationships required when connecting many VNets through a central architecture. Which Azure design is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full public Internet routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent service endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separate Traffic Manager profiles<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke architecture centralizes shared networking services in a hub while connecting multiple workload VNets as spokes. Instead of requiring every spoke to maintain direct peering with every other spoke, the spokes can use the hub for shared services such as firewalls, gateways, routing infrastructure, and centralized inspection. This can simplify network administration as the environment grows. Appropriate routing and security controls are required to ensure that spoke-to-spoke traffic follows the intended path. The architecture is especially useful for organizations seeking centralized governance while maintaining logical separation between application environments.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>An enterprise wants to reduce exposure of backend application servers behind Front Door by ensuring that users access the application through the global Front Door endpoint rather than directly reaching the origin. Which design principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted direct Internet access to the origin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restrict origin access to trusted Front Door traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign public IPs to every backend server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable origin health monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Restricting origin access to trusted Front Door traffic helps reduce the possibility that users will bypass the global application delivery layer and connect directly to backend servers. Front Door can provide the public entry point while the origin is protected through appropriate network and application access controls. The exact implementation depends on the origin type and supported security mechanisms. Administrators should also maintain health monitoring so Front Door can identify available origins. The goal is to ensure that security controls at the origin complement Front Door rather than leaving the backend independently exposed to unrestricted Internet traffic.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>A network architect is designing a large Azure environment where workloads require private service access, centralized inspection, hybrid connectivity, and scalable outbound Internet access. Which approach best represents a layered network architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use public IP addresses on every workload and avoid centralized controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Combine private endpoints, centralized firewalling, hybrid connectivity, and NAT Gateway where appropriate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use only Traffic Manager for all network security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all private connectivity with public Internet access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A layered Azure network architecture uses different services for different connectivity and security requirements rather than relying on a single component. Private endpoints can provide private access to supported Azure services, while centralized firewalling can inspect and control traffic. ExpressRoute or VPN connectivity can support hybrid communication, and NAT Gateway can provide predictable scalable outbound Internet access for appropriate subnets. Network segmentation, routing, DNS, and access controls should complement these services. This approach separates connectivity, inspection, service access, and outbound requirements, making the overall architecture easier to secure and manage as the environment grows.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-700 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 An organization wants to use Azure Firewall Manager to centrally deploy and manage third-party security solutions across Azure virtual hubs. Which capability should the organization use? Private endpoint network policies Security partner provider Traffic Manager multivalue routing Service endpoint Correct Answer: 2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18119"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18119"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18119\/revisions"}],"predecessor-version":[{"id":18120,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18119\/revisions\/18120"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}