Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Microsoft AZ-700 Practice Exam with Questions & Answers | Set: 4

Questions 31

You need to configure FD1 to provide user access to app2.proseware.com. The solution must meet the security requirements and the general requirements.

What should you do first?

Options:
A.

Add a custom domain to FD1.

B.

Add a security policy to FD1.

C.

Request a certificate from a trusted root CA.

D.

Export the TLS certificate and the private key from App2.

Microsoft AZ-700 Premium Access
Questions 32

You have an Azure subscription that contains a web app named App1 and an Azure Web Application Firewall (WAF) on Azure Front Door instance named FD1. FD1 manages traffic for App1.

You solution high levels of traffic to App1, the traffic is detected and blocked automatically. The solution must minimize administrative effort.

What should you include in the solution?

Options:
A.

an IP restriction rule

B.

a WAF exclusion list

C.

a bot protection rule set

D.

a rate limiting rule

Questions 33

Task 8

You plan to deploy an appliance to subnet3-2- The appliance will perform packet inspection and will have an IP address of 10.3.2.100.

You need to ensure that all traffic to the internet from subnet3-1 is forwarded to the appliance for inspection.

Options:
Questions 34

You have an Azure subscription that contains virtual networks, network security groups (NSGs), and virtual machines. You need to perform the following actions:

• Identify unknown traffic between the resources.

• Check the network connectivity between the virtual machines.

What should you use to perform each action? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 34

Options:
Questions 35

Task 1

You plan to deploy a firewall to subnetl-2. The firewall will have an IP address of 10.1.2.4.

You need to ensure that traffic from subnetl-1 to the IP address range of 192.168.10.0/24 is routed through the firewall that will be deployed to subnetl-2. The solution must be achieved without using dynamic routing protocols.

Options:
Questions 36

You have 50 on-premises networks. Each network contains a server that runs Windows Server.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains a database server named DB1.

You plan to deploy an app named App1 that will be hosted on the on-premises servers and will connect to DB1 by using Azure Network Adapter.

What should you use to support the Azure Network Adapter connections to VNet1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 36

Options:
Questions 37

You ate configuring the DNS forwarding luleset for DNSR1

You need to configure the destination IP address for azure.proseware.com and for corp.proseware.com. The solution must meet the general requirements.

Which IP addiesses should you configure for each namespace? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-700 Question 37

Options:
Questions 38

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.

Options:
Questions 39

Task 3

You need to ensure that hosts on VNET1 and VNET2 can communicate. The solution must minimize latency between the virtual networks.

Options:
Questions 40

You need to configure APPGW1 to support end-to-end encryption. The solution must meet the security requirements. What should you do?

Options:
A.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA and includes the full certificate chain.

B.

From the Backend settings, upload a wildcard TLS certificate that has a private key issued by the internal root CA

C.

From the Backend settings, upload the internal root CA certificate.

D.

From the SSL settings, upload a TLS client certificate that is issued by the internal root CA.