Q: 1
You have a hybrid environment that uses ExpressRoute to connect an on-premises network and
Azure.
You need to log the uptime and the latency of the connection periodically by using an Azure virtual
machine and an on-premises virtual machine.
What should you use?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
You have an Azure subscription that contains the resources shown in the following table.
You plan to deploy an Azure Virtual Network NAT gateway named Gateway 1. The solution must
meet the following requirements:
• VM1 will access the internet by using its public IP address.
• VM2 will access the internet by using its public IP address.
• Administrative effort must be minimized.
You need to ensure that you can deploy Gateway1 to Vnet1.
What is the minimal number of subnets that Vnet1 must have?
You plan to deploy an Azure Virtual Network NAT gateway named Gateway 1. The solution must
meet the following requirements:
• VM1 will access the internet by using its public IP address.
• VM2 will access the internet by using its public IP address.
• Administrative effort must be minimized.
You need to ensure that you can deploy Gateway1 to Vnet1.
What is the minimal number of subnets that Vnet1 must have?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
You need to use Traffic Analytics to monitor the usage of applications deployed to Azure virtual
machines.
Which Azure Network Watcher feature should you implement first?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Note: This question is part of a series of questions that present the same scenario. Each question in
the series contains a unique solution that might meet the stated goals. Some question sets might
have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have an Azure application gateway that has Azure Web Application Firewall (WAF) enabled.
You configure the application gateway to direct traffic to the URL of the application gateway.
You attempt to access the URL and receive an HTTP 403 error. You view the diagnostics log and
discover the following error.
You need to ensure that the URL is accessible through the application gateway.
Solution: You create a WAF policy exclusion for request headers that contain 137.135.10.24.
Does this meet the goal?
You need to ensure that the URL is accessible through the application gateway.
Solution: You create a WAF policy exclusion for request headers that contain 137.135.10.24.
Does this meet the goal?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Note: This question is part of a series of questions that present the same scenario. Each question in
the series contains a unique solution that might meet stated goals. Some question sets might have
more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
* A virtual network named Vnet1
* A subnet named Subnet1 in Vnet1
* A virtual machine named VM1 that connects to Subnet1
* Three storage accounts named storage1, storage2. and storage3
You need to ensure that VM1 can access storage1. VM1 must be prevented from accessing any other
storage accounts.
Solution: You create a network security group (NSG). You configure a service tag for MicrosoftStorage
and link the tag to Subnet1.
Does this meet the goal?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
You have an Azure virtual network named Vnet1 that hosts an Azure firewall named FW1 and 150
virtual machines. Vnet1 is linked to a private DNS zone named contoso.com. All the virtual machines
have their name registered in the contoso.com zone.
Vnet1 connects to an on-premises datacenter by using ExpressRoute.
You need to ensure that on-premises DNS servers can resolve the names in the contoso.com zone.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
You have an Azure Web Application Firewall (WAF) policy in prevention mode that is associated to an
Azure Front Door instance.
You need to configure the policy to meet the following requirements:
Log all connections from Australia.
Deny all connections from New Zealand.
Deny all further connections from a network of 131.107.100.0/24 if there are more than 100
connections during one minute.
What is the minimum number of objects you should create?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
You plan to configure BGP for a Site-to-Site VPN connection between a datacenter and Azure.
Which two Azure resources should you configure? Each correct answer presents a part of the
solution. (Choose two.)
NOTE: Each correct selection is worth one point.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
You have an Azure subscription that contains a user named Admin1 and a resource group named
RG1.
RG1 contains an Azure Network Watcher instance named NW1.
You need to ensure that Admin1 can place a lock on NW1. The solution must use the principle of
least privilege.
Which role should you assign to Admin1?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
You are planning the IP addressing for the subnets in Azure virtual networks.
Which type of resource requires IP addresses in the subnets?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2