Microsoft AZ-700 Design And Implement A Web Application Firewall (WAF) Deployment Practice Test

 

AZ-700 skill 5.3 | 36 original questions

This AZ-700 practice set focuses on design and implement a web application firewall (waf) deployment through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 565

Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF; design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7565. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  2. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  3. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  4. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  5. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  6. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.

Correct answers: A, C

Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.

B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.

C: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

D: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.

E: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.

F: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 5.3.1, 5.3.2.

Learning point: AZ700-53-Q565: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall. | Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Question 566

Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7566. Which recommendation most directly meets the requirement? Select one answer.

  1. Use dedicated subnets when a service requires delegation, special routing, or isolation; share only where supported and where policy and scale requirements are compatible.
  2. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  3. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
  4. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  5. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.

Correct answer: D

Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

B: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

C: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

D: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.

E: Not selected. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.8, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

Learning point: AZ700-53-Q566: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Question 567

Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7567. Which recommendation most directly meets the requirement? Select one answer.

  1. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  2. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  3. Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
  4. Create a virtual network link from the Private DNS zone to the required VNet and enable auto-registration only when that VNet should register VM host records.
  5. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Correct answer: E

Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

B: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

C: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

D: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

E: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.

Learning point: AZ700-53-Q567: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Question 568

Alpine Ski House is reviewing a global application estate serving users on three continents. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7568. Which recommendation most directly meets the requirement? Select one answer.

  1. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
  2. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.
  3. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  4. Design Virtual WAN around regional virtual hubs and the required VPN, ExpressRoute, P2S, firewall, and routing services, using hub placement and connectivity intent that match traffic flows and resiliency goals.
  5. Create the Virtual WAN virtual hub in the target region with a nonoverlapping hub address prefix sized for the planned gateways and routing scale.

Correct answer: A

Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.

B: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

D: Not selected. This directly satisfies the requirement to design a Virtual WAN architecture, including selecting types and services. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.2, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

E: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

Learning point: AZ700-53-Q568: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Question 569

Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7569. Which recommendation most directly meets the requirement? Select one answer.

  1. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.
  2. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  3. Deploy Azure DNS Private Resolver with inbound and outbound endpoints and a forwarding ruleset so hybrid DNS queries can traverse between Azure private zones and on-premises DNS without custom DNS VMs.
  4. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answer: B

Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

B: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.

C: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

D: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

Learning point: AZ700-53-Q569: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.

Question 570

Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7570. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  2. Create the Standard Load Balancer with the required frontend, backend pool, health probe, and load-balancing or NAT rules, then validate NSG and return-path behavior.
  3. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  4. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  5. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.

Correct answer: C

Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

B: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

C: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.

D: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

E: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

Learning point: AZ700-53-Q570: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.

Question 571

Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7571. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.
  2. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  3. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  4. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  5. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.

Correct answer: D

Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

B: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

D: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

E: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

Learning point: AZ700-53-Q571: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 572

Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7572. Which recommendation most directly meets the requirement? Select one answer.

  1. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  2. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  3. Create a Public IP Prefix in the target region so deployments can consume a contiguous set of Azure public IP addresses from a reserved prefix.
  4. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  5. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Correct answer: E

Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

C: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

D: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

E: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

Learning point: AZ700-53-Q572: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Question 573

Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7573. Which recommendation most directly meets the requirement? Select one answer.

  1. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  2. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  3. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  4. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.
  5. Choose Azure Load Balancer when the requirement is regional or cross-region Layer 4 load distribution for TCP/UDP services and application-layer inspection is unnecessary.

Correct answer: A

Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.

B: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

Learning point: AZ700-53-Q573: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Question 574

Alpine Ski House is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7574. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  2. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  3. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  4. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  5. Choose Azure NAT Gateway when private-subnet workloads need scalable, predictable outbound SNAT and do not require unsolicited inbound connectivity.

Correct answer: B

Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

B: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.

C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

D: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

Learning point: AZ700-53-Q574: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Question 575

Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7575. Which recommendation most directly meets the requirement? Select one answer.

  1. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  2. Create the Virtual WAN virtual hub in the target region with a nonoverlapping hub address prefix sized for the planned gateways and routing scale.
  3. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
  4. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  5. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.

Correct answer: C

Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

B: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

C: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.

D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

E: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

Learning point: AZ700-53-Q575: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Question 576

Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7576. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  2. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  3. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  4. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answer: D

Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

B: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

D: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

Learning point: AZ700-53-Q576: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.

Question 577

Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7577. Which recommendation most directly meets the requirement? Select one answer.

  1. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  2. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  3. Use Azure Load Balancer for high-performance Layer 4 TCP/UDP distribution with health probes and frontend/backend rules, not for URL-path or host-header routing.
  4. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  5. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.

Correct answer: E

Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

B: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

C: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

D: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6.

E: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.

Learning point: AZ700-53-Q577: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.

Question 578

Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7578. Which recommendation most directly meets the requirement? Select one answer.

  1. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  2. Terminate TLS at the Front Door edge with the managed or customer certificate and use HTTPS to origins with valid certificates when end-to-end encryption is required.
  3. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  4. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.
  5. Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.

Correct answer: A

Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

B: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

C: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

D: Not selected. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

E: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

Learning point: AZ700-53-Q578: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 579

Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7579. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  2. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  3. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  4. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  5. Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.

Correct answer: B

Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

B: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

D: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

E: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

Learning point: AZ700-53-Q579: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Question 580

Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7580. Which recommendation most directly meets the requirement? Select one answer.

  1. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  2. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  3. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  4. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  5. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.

Correct answer: C

Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

B: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

C: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.

D: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

E: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

Learning point: AZ700-53-Q580: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Question 581

Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7581. Which recommendation most directly meets the requirement? Select one answer.

  1. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  2. Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
  3. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  4. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  5. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.

Correct answer: D

Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

C: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

D: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.

E: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

Learning point: AZ700-53-Q581: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Question 582

Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7582. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  2. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  3. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  4. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  5. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Correct answer: E

Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

C: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

E: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.

Learning point: AZ700-53-Q582: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Question 583

Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7583. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  2. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  3. Create the VNet with the approved regional address space, define required subnets, and apply governance before attaching workloads.
  4. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  5. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.

Correct answer: A

Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.

B: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

C: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

D: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

E: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

Learning point: AZ700-53-Q583: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.

Question 584

Alpine Ski House is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy; associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7584. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  2. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  3. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  4. Use Azure Load Balancer for high-performance Layer 4 TCP/UDP distribution with health probes and frontend/backend rules, not for URL-path or host-header routing.
  5. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  6. Use Virtual WAN hub route tables, labels, propagation, and association to control which connections learn which routes and to implement the intended segmentation.

Correct answers: A, B

Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.

B: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

C: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

F: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

Learning point: AZ700-53-Q584: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway. | Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 585

Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7585. Which recommendation most directly meets the requirement? Select one answer.

  1. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  2. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  3. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  4. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  5. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.

Correct answer: B

Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

B: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

C: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

Learning point: AZ700-53-Q585: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 586

Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7586. Which recommendation most directly meets the requirement? Select one answer.

  1. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  2. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
  3. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  4. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  5. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.

Correct answer: C

Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

B: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

C: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

D: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

Learning point: AZ700-53-Q586: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Question 587

Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7587. Which recommendation most directly meets the requirement? Select one answer.

  1. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  2. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.
  3. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  4. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  5. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.

Correct answer: D

Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

C: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

D: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.

E: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

Learning point: AZ700-53-Q587: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Question 588

Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7588. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
  2. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.
  3. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.
  4. Create the NAT Gateway with a public IP or prefix and associate it to the required subnets so outbound flows use the managed SNAT path.
  5. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Correct answer: E

Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.2, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

B: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

C: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

D: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

E: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.

Learning point: AZ700-53-Q588: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Question 589

Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7589. Which recommendation most directly meets the requirement? Select one answer.

  1. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
  2. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  3. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  4. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.
  5. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.

Correct answer: A

Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.

B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

C: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

D: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

Learning point: AZ700-53-Q589: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Question 590

Alpine Ski House is reviewing a regulated production subscription with strict change control. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7590. Which recommendation most directly meets the requirement? Select one answer.

  1. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.
  2. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  3. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  4. Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
  5. Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.

Correct answer: B

Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

B: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.

C: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

D: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

E: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

Learning point: AZ700-53-Q590: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.

Question 591

Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy; associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7591. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  2. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  3. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  4. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  5. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  6. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Correct answers: A, C

Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

B: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

C: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.

D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

F: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7.

Learning point: AZ700-53-Q591: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway. | Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 592

Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7592. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure explicit outbound rules or, preferably where appropriate, a NAT Gateway so SNAT capacity and outbound public addresses are deterministic rather than relying on implicit behavior.
  2. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  3. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  4. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.
  5. Use inbound NAT rules when specific frontend ports must map to individual backend instances for management or specialized per-instance access rather than load-balanced service traffic.

Correct answer: C

Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create and configure explicit outbound rules, including source network address translation (SNAT). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.11, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

B: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

C: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

E: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

Learning point: AZ700-53-Q592: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 593

Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7593. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
  2. Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.
  3. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  4. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  5. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.

Correct answer: D

Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

B: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

C: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

D: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

Learning point: AZ700-53-Q593: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Question 594

Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must design a WAF deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7594. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.
  2. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  3. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.
  4. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  5. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Correct answer: E

Why: 5.3.2: This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

B: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

C: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.2.

E: Correct. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.2: Design a WAF deployment.

Learning point: AZ700-53-Q594: Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.

Question 595

Adventure Works Manufacturing is reviewing a global application estate serving users on three continents. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure detection or prevention mode. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7595. Which recommendation most directly meets the requirement? Select one answer.

  1. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  2. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  3. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  4. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  5. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Correct answer: A

Why: 5.3.3: This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.3: Configure detection or prevention mode.

B: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

C: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 5.3.3.

Learning point: AZ700-53-Q595: Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.

Question 596

Alpine Ski House is reviewing a regulated production subscription with strict change control. Global users need a low-latency HTTP(S) entry point with health-aware origin selection and edge capabilities. The network engineer must configure rule sets for WAF on Azure Front Door. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7596. Which recommendation most directly meets the requirement? Select one answer.

  1. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.
  2. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Create a Standard public IP address with the required allocation, zone, and routing preference settings, then protect and monitor the resource as part of the workload design.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.

Correct answer: B

Why: 5.3.4: This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

B: Correct. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.4: Configure rule sets for WAF on Azure Front Door.

C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

D: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.4.

Learning point: AZ700-53-Q596: Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Question 597

Adventure Works Manufacturing is reviewing an environment where IP allowlists are maintained by external partners. The application needs regional HTTP(S) routing and health-aware delivery without moving routing logic into the application. The network engineer must configure rule sets for WAF on Application Gateway. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7597. Which recommendation most directly meets the requirement? Select one answer.

  1. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  2. Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
  3. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  4. Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
  5. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.

Correct answer: C

Why: 5.3.5: This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

B: Not selected. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.3, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

C: Correct. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.5: Configure rule sets for WAF on Application Gateway.

D: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.5.

Learning point: AZ700-53-Q597: Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.

Question 598

Alpine Ski House is reviewing a global application estate serving users on three continents. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must implement a WAF policy; associate a WAF policy; map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7598. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  2. Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.
  3. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  4. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  5. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  6. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Correct answers: A, D, F

Why: 5.3.6: This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.6: Implement a WAF policy.

B: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7, 5.3.1.

C: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7, 5.3.1.

D: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

E: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.3.6, 5.3.7, 5.3.1.

F: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

Learning point: AZ700-53-Q598: Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway. | Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced. | Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Question 599

Adventure Works Manufacturing is reviewing a regulated production subscription with strict change control. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must associate a WAF policy. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7599. Which recommendation most directly meets the requirement? Select one answer.

  1. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.
  2. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
  3. Use inbound NAT rules when specific frontend ports must map to individual backend instances for management or specialized per-instance access rather than load-balanced service traffic.
  4. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  5. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Correct answer: D

Why: 5.3.7: This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.9, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

B: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

C: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

D: Correct. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.7: Associate a WAF policy.

E: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.3.7.

Learning point: AZ700-53-Q599: Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.

Question 600

Alpine Ski House is reviewing an environment where IP allowlists are maintained by external partners. The public web application is seeing malicious HTTP requests and needs managed application-layer protection with controlled rollout. The network engineer must map requirements to features and capabilities of WAF. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7600. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  2. Create a Public IP Prefix in the target region so deployments can consume a contiguous set of Azure public IP addresses from a reserved prefix.
  3. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  4. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  5. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Correct answer: E

Why: 5.3.1: This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

B: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

C: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

D: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.3.1.

E: Correct. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.3.1: Map requirements to features and capabilities of WAF.

Learning point: AZ700-53-Q600: Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.

Popular posts

img