Free AZ-700 Practice Test

Free Microsoft AZ-700 Practice Test

Azure Network Engineer Associate (AZ‑700) certification - Practice Tests/Quiz Exam Questions

1 / 80

A network engineer wants to monitor packet capture data and diagnose connectivity issues between Azure VMs.
Which tool should be used?

2 / 80

A global application needs to route users to the closest Azure region based on geographic location and DNS resolution.
Which service is MOST appropriate?

3 / 80

A company wants to ensure that Azure PaaS services such as storage accounts are accessible only from a specific VNet and not over public endpoints.
Which feature should be used?

4 / 80

A network engineer needs to route traffic from a subnet through a network virtual appliance (NVA) before reaching the internet.
What should be configured?

5 / 80

A company uses Azure Virtual Machines and wants to allow secure RDP access without exposing public IP addresses.
Which solution is BEST?

6 / 80

A company wants to ensure that Azure resources are protected from volumetric network attacks targeting public IP addresses.
Which service should be implemented?

7 / 80

A web application hosted in Azure must distribute incoming traffic across multiple backend servers based on URL paths. The solution must operate at Layer 7.
Which service should be used?

8 / 80

A company wants to connect its on-premises network to Azure using a private, dedicated connection that does not traverse the public internet.
Which service BEST meets this requirement?

9 / 80

A network engineer needs to restrict inbound traffic to a subnet so only HTTPS traffic from a specific IP range is allowed. All other traffic must be denied.
Which Azure feature should be used?

10 / 80

A company deploys multiple Azure Virtual Networks (VNets) across regions and needs private communication between them without exposing traffic to the internet. The solution must minimize latency and avoid additional gateways.
What is the BEST solution?

11 / 80

A network engineer must ensure that Azure storage accounts are accessible only from a specific subnet and not from the public internet.
What should be configured?

12 / 80

A company wants to provide secure access to Azure VMs without exposing management ports to the internet. Administrators must connect through a browser.
What should be implemented?

13 / 80

A company needs to restrict inbound HTTPS traffic to a web application so only a specific IP range is allowed. All other inbound traffic must be blocked.
What should be configured?

14 / 80

A network engineer must ensure that traffic between two VNets in different regions remains private and does not traverse the public internet. The solution should not require gateways.
What should be used?

15 / 80

A company deploys a hub-and-spoke network and needs to ensure all outbound traffic from spokes is inspected by a firewall in the hub. Traffic must not bypass the firewall under any condition.
What should be configured?

16 / 80

Intermittent connectivity issues occur between VNets in different regions. Peering is configured, but traffic does not always flow.

What is the MOST likely cause?

17 / 80

The company needs DNS resolution between Azure VNets and on-premises systems without deploying DNS servers in each VNet.

What should be implemented?

18 / 80

Users report inconsistent latency when accessing the web application globally. The company wants to route users to the closest region dynamically.

What should be configured?

 

19 / 80

The company wants to ensure that backend APIs are not accessible from the internet but remain reachable by frontend applications in other VNets.

What should be used?

 

20 / 80

Traffic from spoke VNets sometimes bypasses the Azure Firewall when accessing external endpoints. The engineer needs to ensure that all outbound traffic is always inspected.

What should be implemented?

21 / 80

The company requires automatic failover between ExpressRoute and VPN connections without manual intervention.

What must be enabled?

22 / 80

DNS resolution between VNets in different regions intermittently fails. The company wants a centralized and scalable solution.

What should be configured?

23 / 80

Cross-region communication between VNets must remain private and avoid using VPN or ExpressRoute gateways.

What should be used?

24 / 80

The company wants to ensure that backend APIs are never exposed publicly but remain accessible to frontend services across VNets and regions.

What should be implemented?

25 / 80

Outbound traffic from spoke VNets sometimes reaches the internet without passing through Azure Firewall. The engineer must enforce inspection for all outbound flows.

What should be configured?

26 / 80

A company needs dynamic routing between Azure and on-premises networks that automatically adjusts during failover.
What should be used?

27 / 80

A subnet must only allow deployment of specific Azure services.
What should be configured?

28 / 80

A company needs global routing with SSL termination at edge locations for improved performance.
What should be used?

29 / 80

A subnet must route all traffic through a network virtual appliance before reaching its destination.
What should be configured?

30 / 80

A network engineer must monitor latency between Azure resources without installing agents. The solution should provide ongoing visibility.
What should be used?

31 / 80

A company needs to distribute HTTP traffic across backend servers while routing based on URL paths and inspecting headers.
What should be used?

32 / 80

A company wants Azure PaaS services to be accessible only through private IP addresses and not through public endpoints.
What should be implemented?

33 / 80

A company needs to allow communication between two subnets but only over TCP port 443. All other traffic must be blocked, and routing must remain unchanged.
What should be configured?

34 / 80

A subnet contains multiple VMs that must access external services using a consistent public IP address. The solution must scale automatically and require minimal management.
What should be implemented?

35 / 80

A company deploys multiple VNets and requires private connectivity between them without allowing transit through a third VNet. Each connection must be explicitly configured and controlled.
What should be used?

36 / 80

An organization wants to allow resources in two VNets in different Azure regions to communicate using private IP addresses. Which feature should be configured?

37 / 80

Which Azure feature provides outbound internet connectivity for resources in a private subnet without requiring a public IP address on each individual resource?

38 / 80

A company wants to route traffic between two VNets through a central network virtual appliance for inspection, rather than routing directly. Which feature enables this?

39 / 80

Which Azure service allows a customer to bring their own publicly routable IP address range (BYOIP) for use as Azure public IP addresses?

40 / 80

Which Azure DNS feature allows on-premises servers to resolve Azure private DNS zone records, and Azure resources to resolve on-premises DNS records, through a hybrid resolution mechanism?

41 / 80

Which centralized management tool allows an organization to apply consistent network security and connectivity configurations across multiple VNets at scale, using group-based targeting?

42 / 80

A subnet hosting Azure Application Gateway requires a dedicated subnet with no other resource types deployed. This requirement is an example of which design consideration?

43 / 80

Which routing feature allows an organization to exchange routes dynamically between network virtual appliances and the Azure VNet using BGP, without manually configuring static UDRs for every route?

44 / 80

A company needs to segment a large address space across multiple subnets while ensuring specific subnets are reserved for gateway, firewall, and Bastion resources. Which planning activity does this describe?

45 / 80

Which statement correctly describes a key limitation of VNet peering regarding transitive routing?

46 / 80

Which ExpressRoute feature allows two ExpressRoute circuits connected to different Microsoft Enterprise Edge (MSEE) routers to communicate directly with each other, enabling connectivity between two on-premises sites without traversing the public internet?

47 / 80

Which ExpressRoute feature improves data path performance by allowing traffic to bypass the ExpressRoute virtual network gateway, sending traffic directly from the on-premises network to the VM in the VNet?

48 / 80

Which VPN Gateway SKU consideration determines whether the gateway can support active-active configuration for improved resiliency, using two gateway instances simultaneously handling traffic?

49 / 80

Which Azure networking service provides a unified hub-and-spoke architecture that combines SD-WAN-like connectivity, VPN, and ExpressRoute connections into a single managed service?

50 / 80

A company needs individual remote users to securely connect to Azure VNet resources from their laptops, without a site-to-site tunnel to an entire office network. Which connectivity option is most appropriate?

51 / 80

Which routing protocol is used by ExpressRoute private peering to dynamically exchange routes between the on-premises network and Azure?

52 / 80

Which ExpressRoute peering type is specifically used to connect to Microsoft 365 services, such as Exchange Online and SharePoint Online, rather than to private Azure VNets?

53 / 80

Which factor most directly determines the maximum available bandwidth for an ExpressRoute connection?

54 / 80

Which Virtual WAN component acts as the regional hub that connects branch sites, VPN connections, and ExpressRoute circuits, and can also host security services like Azure Firewall?

55 / 80

A company wants to ensure that if one ExpressRoute circuit fails, traffic automatically fails over to a Site-to-Site VPN connection as a backup path. Which design consideration supports this?

56 / 80

Which Azure load balancing service operates at Layer 7 and can make routing decisions based on URL path, making it suitable for hosting multiple web applications behind a single entry point?

57 / 80

Which feature of Application Gateway inspects incoming web traffic for common exploits, such as SQL injection and cross-site scripting, before it reaches the backend application?

58 / 80

Which Azure load balancing service operates at the DNS layer, directing client requests to the most appropriate service endpoint across multiple regions based on a routing method, rather than load balancing individual packets?

59 / 80

Which Azure global service combines a global content delivery network with application acceleration, Layer 7 load balancing, and a Web Application Firewall, optimized for globally distributed web applications?

60 / 80

Which Azure Load Balancer SKU is required to support features such as availability zones and NSG requirements for backend resources in a production environment?

61 / 80

Which Application Gateway routing capability directs traffic based on the incoming request's hostname, allowing multiple domains to be served through the same gateway with different backend pools?

62 / 80

Which Application Gateway feature ensures that requests from the same client session are consistently routed to the same backend server, important for stateful applications?

63 / 80

Which Traffic Manager routing method directs traffic to the endpoint with the lowest network latency for the requesting client?

64 / 80

Which Traffic Manager routing method is appropriate for directing traffic to a single primary endpoint under normal conditions, automatically failing over to a designated secondary endpoint if the primary becomes unavailable?

65 / 80

Which Azure feature assigns a private IP address from within a VNet directly to a specific PaaS service instance, such as a specific storage account, effectively bringing that service into the VNet's private address space?

66 / 80

Which Azure feature extends a VNet's identity to a PaaS service over the Azure backbone network, without assigning the service a private IP address, and applies at the subnet level rather than to a specific service instance?

67 / 80

After creating a Private Endpoint for an Azure SQL Database, which additional DNS configuration is typically required to ensure clients resolve the database's fully qualified domain name to the private IP address rather than the public one?

68 / 80

Which Azure Private Link capability allows a service provider to expose their own custom service securely to consumers in other VNets, potentially across different subscriptions or tenants, via a Private Endpoint?

69 / 80

Which Azure resource allows an administrator to group multiple VMs by role, such as 'WebServers,' and apply NSG rules to that group rather than to individual IP addresses?

70 / 80

Which Azure Firewall rule type is used to filter traffic based on fully qualified domain names (FQDNs), such as allowing outbound access only to specific approved websites?

71 / 80

Which Azure Firewall rule type is used to filter traffic based on source and destination IP address, port, and protocol, similar to a traditional network firewall rule?

72 / 80

Which Azure Firewall rule type translates inbound traffic destined for the firewall's public IP address to a private IP address and port within the VNet?

73 / 80

Which Azure DDoS Protection tier provides enhanced mitigation capabilities, cost protection, and access to a rapid response team, beyond the protections included automatically with every Azure VNet?

74 / 80

Which Azure service provides secure RDP and SSH connectivity to VMs directly through the Azure portal, without requiring a public IP address on the VM or exposing RDP/SSH ports to the internet?

75 / 80

Which Network Watcher feature allows an administrator to capture and analyze actual network traffic on a specific VM for detailed troubleshooting, similar to a traditional packet sniffer?

76 / 80

Which Network Watcher feature records information about IP traffic flowing through a Network Security Group, including which flows were allowed or denied, for auditing and analysis purposes?

77 / 80

Which Network Watcher feature allows an administrator to quickly check whether a specific NSG rule would allow or deny a particular hypothetical traffic flow, without generating actual traffic?

78 / 80

Which Network Watcher feature continuously monitors connectivity and latency between a source and destination endpoint, alerting on connectivity issues over time?

79 / 80

Which security consideration determines the order in which Azure Firewall Policy rule collections are evaluated when a policy includes both a base policy and a child policy inherited from it?

80 / 80

A company wants to ensure that traffic between two subnets within the same VNet is inspected by Azure Firewall rather than routed directly, even though they could otherwise communicate freely by default. Which combination of configurations achieves this?

Your score is

The average score is 87%

0%