Cyber Monday Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

AZ-700 Microsoft Designing and Implementing Microsoft Azure Networking Solutions Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Microsoft AZ-700 Designing and Implementing Microsoft Azure Networking Solutions certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 2 / 4
Total 306 questions

You have an Azure virtual network and an on-premises datacenter that connect by using a Site-to-Site VPN tunnel.

You need to ensure that all traffic from the virtual network to the internet is routed through the datacenter.

How should you complete the PowerShell script to configure forced tunneling? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 has a subnet mask of /24. You plan to implement an Azure application gateway that will have the following configurations:

• Public endpoints: 1

• Private endpoints: 1

• Minimum instances: 1

• Maximum instances: 10

You need to configure the address space for the subnet of the application gateway. The solution must minimize the number of IP addresses allocated to the application gateway subnet.

What is the minimum number of assignable IP addresses required?

A.

1

B.

2

C.

11

D.

12

E.

20

You have an Azure subscription that contains a web app named App1 and an Azure Web Application Firewall (WAF) on Azure Front Door instance named FD1. FD1 manages traffic for App1.

You solution high levels of traffic to App1, the traffic is detected and blocked automatically. The solution must minimize administrative effort.

What should you include in the solution?

A.

an IP restriction rule

B.

a WAF exclusion list

C.

a bot protection rule set

D.

a rate limiting rule

You have an on-premises VPN appliance named GW1.

You have an Azure subscription that contains an Azure VPN gateway named VPNGW1. VPNGW1 connects to GW1.

You need to modify the IKEv2 encryption algorithm used by VPNGW1 and GW1.

Which PowerShell cmdlet should you run? To answer, select the appropriate options in the answer area.

NOTE Each correct selection is worth one point.

Task 4

You need to ensure that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name storage34280945.pnvatelinlcblob.core.windows.net.

Task 2

You need to create an Azure Firewall instance named FW1 that meets the following requirements:

• Has an IP address from the address range of 10.1.255.0/24

• Uses a new Premium firewall policy named FW-pohcy1

• Routes traffic directly to the internet

Task 2

You need to ensure that you can deploy Azure virtual machines to the France Central Azure region. The solution must ensure that virtual machines in the France Central region are in a network segment that has an IP address range of 10.5.1.0/24.

You have an Azure subscription that contains an Azure Front Door named FD1.

You plan to deploy an app named App1 by using Azure App Service. Users will access App1 by using FD1.

You need to provide FD1 with access to Appl. The solution must meet the following requirements:

• Ensure that users can only access App1 by using FD1.

• Ensure that users cannot access App1 directly from the internet.

What should you create for App1?

A.

a subnet delegation

B.

a service endpoint

C.

an access restriction

D.

a private endpoint

Task 11

You are preparing to connect your on-premises network to VNET4 by using a Site-to-Site VPN. The on-premises endpoint of the VPN will be created on a firewall named Firewall 1.

The on-premises network has the following configurations:

• Internal address range: 10.10.0.0/16.

• Firewall 1 internal IP address: 10.10.1.1.

• Firewall1 public IP address: 131.107.50.60.

BGP is NOT used.

You need to create the object that will provide the IP addressing configuration of the on-premises network to the Site-to-Site VPN. You do NOT need to create a virtual network gateway to complete this task.

Task 5

You need to archive all the metrics of VNET1 to an existing storage account.

Task 8

You plan to deploy an appliance to subnet3-2- The appliance will perform packet inspection and will have an IP address of 10.3.2.100.

You need to ensure that all traffic to the internet from subnet3-1 is forwarded to the appliance for inspection.

Task 1

You need to ensure that virtual machines on VNET1 and VNET2 are included automatically in a DNS zone named contoso.azure. The solution must ensure that the virtual machines on VNET1 and VNET2 can resolve the names of the virtual machines on either virtual network.

You have an Azure subscription that contains a virtual network named VNetl and the resources shown in the following table.

You need to implement a solution for the traffic onginating from VNetl. The solution must meet the following requirements:

• Perform transparent proxying to external web servers.

• Inspect all outbound TLS traffic.

• Minimize costs.

Which resource should you include in the solution?

A.

FD1

B.

FW1

C.

AG1

D.

FW2

Task 10

You plan to deploy several virtual machines to subnet1-2.

You need to prevent all Azure hosts outside of subnetl-2 from connecting to TCP port 5585 on hosts on subnet1-2. The solution must minimize administrative effort.

You have an Azure subscription that contains virtual networks, network security groups (NSGs), and virtual machines. You need to perform the following actions:

• Identify unknown traffic between the resources.

• Check the network connectivity between the virtual machines.

What should you use to perform each action? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Task 5

You need to ensure that requests for wwwjelecloud.com from any of your Azure virtual networks resolve to frontdoor1.azurefd.net.

You have an on premises web server that hosts a web app named App1 and has the following configurations:

• IP address 131.107.50.60

• FQDN server1.contoso.com

You have an Azure subscription.

You need to publish App1 by using Azure Front Door. The solution must meet the following requirements:

• Ensure that internet users can connect to App1 by using an FQDN of appl.contoso.com.

• Minimize the changes required to the configuration of Front Door if Server 1 is migrated to Azure.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have the hybrid network shown in the Network Diagram exhibit.

You have a peering connection between Vnet1 and Vnet2 as shown in the Peering-Vnet1-Vnet2 exhibit.

You have a peering connection between Vnet1 and Vnet3 as shown in the Peering -Vnet1-Vnet3 exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

In which NSGs can you use ASG1 and to which virtual machine network interfaces can you associate ASG1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Page: 2 / 4
Total 306 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved