Microsoft AZ-700 Design And Implement Azure Firewall And Azure Firewall Manager Practice Test

 

AZ-700 skill 5.2 | 36 original questions

This AZ-700 practice set focuses on design and implement azure firewall and azure firewall manager through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 529

Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7529. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  2. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  3. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  4. Create the Virtual WAN virtual hub in the target region with a nonoverlapping hub address prefix sized for the planned gateways and routing scale.
  5. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.

Correct answer: B

Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

B: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

C: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

D: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

E: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

Learning point: AZ700-52-Q529: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.

Question 530

Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU; design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7530. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  2. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  3. Use inbound NAT rules when specific frontend ports must map to individual backend instances for management or specialized per-instance access rather than load-balanced service traffic.
  4. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.
  5. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  6. Use nonoverlapping CIDR ranges, segment workloads by trust and function, reserve capacity for growth, and validate peering and hybrid address-space conflicts before deployment.

Correct answers: A, B

Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

B: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

C: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

D: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

E: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

F: Not selected. This directly satisfies the requirement to plan and implement network segmentation and address spaces. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

Learning point: AZ700-52-Q530: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost. | Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Question 531

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7531. Which recommendation most directly meets the requirement? Select one answer.

  1. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.
  2. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  3. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  4. Create the appropriate Azure DNS zones and record sets, separating public authoritative records from private records and applying the required TTL and VNet-link configuration.
  5. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.

Correct answer: C

Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

C: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

D: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

E: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

Learning point: AZ700-52-Q531: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Question 532

Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment; configure Azure Firewall rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7532. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  2. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  3. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.
  4. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  5. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  6. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.

Correct answers: E, F

Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

B: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

E: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

F: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

Learning point: AZ700-52-Q532: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically. | Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.

Question 533

Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7533. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  2. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  5. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  6. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.

Correct answers: A, F

Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

B: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

D: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

F: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

Learning point: AZ700-52-Q533: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 534

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create and implement Azure Firewall Manager policies; create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7534. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  2. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  3. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  4. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  5. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  6. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Correct answers: D, F

Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

B: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

D: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

F: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

Learning point: AZ700-52-Q534: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration. | Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 535

Proseware Media is reviewing a global application estate serving users on three continents. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7535. Which recommendation most directly meets the requirement? Select one answer.

  1. Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
  2. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  3. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  4. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
  5. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.

Correct answer: D

Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

B: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

C: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

D: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

Learning point: AZ700-52-Q535: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 536

Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall; select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7536. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  2. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  3. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  4. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  5. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  6. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Correct answers: C, D

Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

B: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

C: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

D: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

F: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

Learning point: AZ700-52-Q536: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks. | Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.

Question 537

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU; design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7537. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  2. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  3. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  4. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  5. Create a virtual network link from the Private DNS zone to the required VNet and enable auto-registration only when that VNet should register VM host records.
  6. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.

Correct answers: A, D

Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

B: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

C: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

E: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

F: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

Learning point: AZ700-52-Q537: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost. | Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Question 538

Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment; create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7538. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  3. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  4. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  5. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  6. Control private-endpoint reachability with routing, DNS, NSGs where supported, and service-side public-network settings so only approved private clients can reach the resource.

Correct answers: B, D

Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

B: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

C: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

E: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

F: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

Learning point: AZ700-52-Q538: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules. | Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.

Question 539

Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment; configure Azure Firewall rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7539. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  2. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  3. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  4. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  5. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  6. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Correct answers: A, E

Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

B: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

D: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

E: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

F: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.2, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.

Learning point: AZ700-52-Q539: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically. | Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.

Question 540

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7540. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  2. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  3. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  4. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  5. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  6. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.

Correct answers: B, C

Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

B: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

C: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

F: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

Learning point: AZ700-52-Q540: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 541

Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7541. Which recommendation most directly meets the requirement? Select one answer.

  1. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  2. Configure the VNet to use the intended Azure-provided or custom DNS servers and ensure clients renew their DHCP configuration so the new resolver settings take effect.
  3. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
  4. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  5. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Correct answer: E

Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

B: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

C: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.2, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

D: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

E: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

Learning point: AZ700-52-Q541: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 542

Wingtip Services is reviewing a regulated production subscription with strict change control. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7542. Which recommendation most directly meets the requirement? Select one answer.

  1. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
  2. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  3. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.
  4. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  5. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.

Correct answer: A

Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

C: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

E: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

Learning point: AZ700-52-Q542: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 543

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7543. Which recommendation most directly meets the requirement? Select one answer.

  1. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  2. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  3. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.
  4. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.
  5. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Correct answer: B

Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

B: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

E: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

Learning point: AZ700-52-Q543: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.

Question 544

Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7544. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.
  2. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  3. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  4. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  5. Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.

Correct answer: C

Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

C: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

D: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

E: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

Learning point: AZ700-52-Q544: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.

Question 545

Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7545. Which recommendation most directly meets the requirement? Select one answer.

  1. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  2. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  5. Onboard the organization-owned public range as a Custom IP Prefix, complete Microsoft validation and provisioning, and then allocate public IP prefixes or addresses from the BYOIP range.

Correct answer: D

Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

E: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

Learning point: AZ700-52-Q545: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Question 546

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment; configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7546. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.
  2. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  3. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  4. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  5. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  6. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.

Correct answers: B, D, F

Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5, 5.2.6.

B: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

C: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5, 5.2.6.

D: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

E: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5, 5.2.6.

F: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

Learning point: AZ700-52-Q546: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically. | Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 547

Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7547. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.
  2. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  5. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  6. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Correct answers: B, F

Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

B: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

D: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

E: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

F: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

Learning point: AZ700-52-Q547: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 548

Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create and implement Azure Firewall Manager policies; create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7548. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  2. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  3. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
  4. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  5. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  6. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.

Correct answers: B, C

Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

B: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

C: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

D: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

F: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

Learning point: AZ700-52-Q548: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration. | Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 549

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7549. Which recommendation most directly meets the requirement? Select one answer.

  1. Terminate TLS at the Front Door edge with the managed or customer certificate and use HTTPS to origins with valid certificates when end-to-end encryption is required.
  2. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  5. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Correct answer: E

Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

C: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

D: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

E: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

Learning point: AZ700-52-Q549: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 550

Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7550. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  2. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  3. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  4. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  5. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.

Correct answer: A

Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

B: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

C: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

D: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

E: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

Learning point: AZ700-52-Q550: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.

Question 551

Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU; design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7551. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Onboard the organization-owned public range as a Custom IP Prefix, complete Microsoft validation and provisioning, and then allocate public IP prefixes or addresses from the BYOIP range.
  2. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  3. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  4. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  5. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  6. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.

Correct answers: D, E

Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

B: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

C: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

D: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

E: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

F: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.

Learning point: AZ700-52-Q551: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost. | Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Question 552

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7552. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
  2. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  3. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  4. Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
  5. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.

Correct answer: B

Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

B: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

C: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

D: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

E: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.3.

Learning point: AZ700-52-Q552: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Question 553

Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7553. Which recommendation most directly meets the requirement? Select one answer.

  1. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  2. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  3. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  4. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  5. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.

Correct answer: C

Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

C: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

Learning point: AZ700-52-Q553: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.

Question 554

Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7554. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  2. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  3. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  4. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  5. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  6. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Correct answers: C, F

Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

B: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

C: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

D: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

E: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

F: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

Learning point: AZ700-52-Q554: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 555

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7555. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Virtual WAN hub route tables, labels, propagation, and association to control which connections learn which routes and to implement the intended segmentation.
  2. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  3. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  4. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  5. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.

Correct answer: D

Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

C: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

D: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

E: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.6.

Learning point: AZ700-52-Q555: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 556

Wingtip Services is reviewing a global application estate serving users on three continents. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7556. Which recommendation most directly meets the requirement? Select one answer.

  1. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  2. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.
  3. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  4. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  5. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Correct answer: E

Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

B: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

C: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

D: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.7.

E: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

Learning point: AZ700-52-Q556: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 557

Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7557. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  2. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  3. Use Virtual WAN hub route tables, labels, propagation, and association to control which connections learn which routes and to implement the intended segmentation.
  4. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  5. Create the Virtual WAN virtual hub in the target region with a nonoverlapping hub address prefix sized for the planned gateways and routing scale.

Correct answer: A

Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

C: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

E: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.

Learning point: AZ700-52-Q557: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.

Question 558

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7558. Which recommendation most directly meets the requirement? Select one answer.

  1. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  2. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  3. Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
  4. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  5. Create the Virtual WAN virtual hub in the target region with a nonoverlapping hub address prefix sized for the planned gateways and routing scale.

Correct answer: B

Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

B: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

C: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

D: Not selected. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.3, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

E: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.2.2.

Learning point: AZ700-52-Q558: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.

Question 559

Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment; create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7559. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  2. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  3. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  4. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  5. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  6. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.

Correct answers: B, D

Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

B: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

C: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.

E: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

F: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.

Learning point: AZ700-52-Q559: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules. | Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.

Question 560

Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7560. Which recommendation most directly meets the requirement? Select one answer.

  1. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  2. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  3. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  4. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  5. Control private-endpoint reachability with routing, DNS, NSGs where supported, and service-side public-network settings so only approved private clients can reach the resource.

Correct answer: C

Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

C: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.

D: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

E: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 5.2.4.

Learning point: AZ700-52-Q560: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.

Question 561

Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7561. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  3. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  4. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  5. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  6. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Correct answers: E, F

Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

C: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.

E: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.

F: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

Learning point: AZ700-52-Q561: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.

Question 562

Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create and implement Azure Firewall Manager policies; create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7562. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Size each Virtual WAN gateway using the service’s scale units based on expected aggregate throughput, connection count, and resiliency requirements, then monitor utilization for growth.
  2. Create the appropriate Azure DNS zones and record sets, separating public authoritative records from private records and applying the required TTL and VNet-link configuration.
  3. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  4. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  5. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  6. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Correct answers: E, F

Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

B: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

C: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.

E: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.

F: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

Learning point: AZ700-52-Q562: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration. | Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.

Question 563

Proseware Media is reviewing a regulated production subscription with strict change control. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub; map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7563. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  2. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  3. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
  4. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  5. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  6. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.

Correct answers: C, D

Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.

B: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.

C: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.

D: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

E: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.

F: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.

Learning point: AZ700-52-Q563: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected. | Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.

Question 564

Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall; select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7564. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  2. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  3. Create a Standard public IP address with the required allocation, zone, and routing preference settings, then protect and monitor the resource as part of the workload design.
  4. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  5. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  6. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.

Correct answers: E, F

Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

B: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

C: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

D: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.

E: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.

F: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.

Learning point: AZ700-52-Q564: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks. | Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.

Popular posts

img