Microsoft AZ-700 Design And Implement Azure Firewall And Azure Firewall Manager Practice Test
AZ-700 skill 5.2 | 36 original questions
This AZ-700 practice set focuses on design and implement azure firewall and azure firewall manager through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.
Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.
Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7529. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
B: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
C: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
D: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
E: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
Learning point: AZ700-52-Q529: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU; design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7530. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, B
Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
B: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
C: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
D: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
E: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
F: Not selected. This directly satisfies the requirement to plan and implement network segmentation and address spaces. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
Learning point: AZ700-52-Q530: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost. | Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7531. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
C: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
D: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
E: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
Learning point: AZ700-52-Q531: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment; configure Azure Firewall rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7532. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: E, F
Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
B: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
E: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
F: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
Learning point: AZ700-52-Q532: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically. | Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7533. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, F
Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
B: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
D: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
E: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
F: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
Learning point: AZ700-52-Q533: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create and implement Azure Firewall Manager policies; create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7534. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, F
Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
B: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
D: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
F: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
Learning point: AZ700-52-Q534: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration. | Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Proseware Media is reviewing a global application estate serving users on three continents. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7535. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
B: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
C: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
D: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
Learning point: AZ700-52-Q535: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall; select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7536. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, D
Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
B: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
C: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
D: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
E: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
F: Not selected. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
Learning point: AZ700-52-Q536: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks. | Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU; design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7537. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, D
Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
B: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
C: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
E: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
F: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
Learning point: AZ700-52-Q537: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost. | Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment; create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7538. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, D
Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
B: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
C: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
E: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
F: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
Learning point: AZ700-52-Q538: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules. | Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment; configure Azure Firewall rules. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7539. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, E
Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
B: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
D: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
E: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
F: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.2, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5.
Learning point: AZ700-52-Q539: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically. | Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7540. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, C
Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
B: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
C: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
F: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
Learning point: AZ700-52-Q540: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7541. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
B: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
C: Not selected. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.2, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
D: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
E: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
Learning point: AZ700-52-Q541: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Wingtip Services is reviewing a regulated production subscription with strict change control. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7542. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
C: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
E: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
Learning point: AZ700-52-Q542: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7543. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
B: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
E: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
Learning point: AZ700-52-Q543: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7544. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
C: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
D: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
E: Not selected. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.4, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
Learning point: AZ700-52-Q544: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7545. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
E: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
Learning point: AZ700-52-Q545: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment; configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7546. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: B, D, F
Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5, 5.2.6.
B: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
C: Not selected. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.4, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5, 5.2.6.
D: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
E: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4, 5.2.5, 5.2.6.
F: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
Learning point: AZ700-52-Q546: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically. | Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7547. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, F
Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
B: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
D: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
E: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
F: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
Learning point: AZ700-52-Q547: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create and implement Azure Firewall Manager policies; create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7548. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, C
Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
B: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
C: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
D: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
F: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
Learning point: AZ700-52-Q548: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration. | Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7549. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
C: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
D: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
E: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
Learning point: AZ700-52-Q549: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7550. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
B: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
C: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
D: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
E: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
Learning point: AZ700-52-Q550: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU; design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7551. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, E
Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
B: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
C: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
D: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
E: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
F: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.2, 5.2.3.
Learning point: AZ700-52-Q551: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost. | Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7552. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
B: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
C: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
D: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
E: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.3.
Learning point: AZ700-52-Q552: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7553. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
C: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
Learning point: AZ700-52-Q553: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7554. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, F
Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
B: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
C: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
D: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
E: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
F: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
Learning point: AZ700-52-Q554: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7555. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
C: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
D: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
E: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.6.
Learning point: AZ700-52-Q555: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Wingtip Services is reviewing a global application estate serving users on three continents. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7556. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
B: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
C: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
D: Not selected. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.7.
E: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
Learning point: AZ700-52-Q556: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Proseware Media is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7557. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
C: Not selected. This directly satisfies the requirement to configure virtual hub routing. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
D: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
E: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1.
Learning point: AZ700-52-Q557: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7558. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
B: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
C: Not selected. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.13, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
D: Not selected. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.3, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
E: Not selected. This directly satisfies the requirement to create a virtual hub in Virtual WAN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.3, but it does not directly satisfy the scenario requirement mapped to 5.2.2.
Learning point: AZ700-52-Q558: Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
Proseware Media is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must design an Azure Firewall deployment; create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7559. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, D
Why: 5.2.3: This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
B: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
C: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
D: Correct. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.3: Design an Azure Firewall deployment.
E: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
F: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.3, 5.2.4.
Learning point: AZ700-52-Q559: Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules. | Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
Wingtip Services is reviewing a regulated production subscription with strict change control. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create and implement an Azure Firewall deployment. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7560. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 5.2.4: This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
C: Correct. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.4: Create and implement an Azure Firewall deployment.
D: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
E: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 5.2.4.
Learning point: AZ700-52-Q560: Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
Proseware Media is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must configure Azure Firewall rules; create and implement Azure Firewall Manager policies. The design must scale automatically as traffic grows, and the decision will be reviewed by the business continuity lead. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7561. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: E, F
Why: 5.2.5: This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
C: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.5, 5.2.6.
E: Correct. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.5: Configure Azure Firewall rules.
F: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
Learning point: AZ700-52-Q561: Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies. | Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
Wingtip Services is reviewing a global application estate serving users on three continents. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The network engineer must create and implement Azure Firewall Manager policies; create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The design must scale automatically as traffic grows, and the decision will be reviewed by the platform governance council. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7562. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: E, F
Why: 5.2.6: This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose an appropriate scale unit for each gateway type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.4, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
B: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
C: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.6, 5.2.7.
E: Correct. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.6: Create and implement Azure Firewall Manager policies.
F: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
Learning point: AZ700-52-Q562: Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration. | Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
Proseware Media is reviewing a regulated production subscription with strict change control. The current branch connectivity model does not scale across regions and policy is inconsistent between hubs. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub; map requirements to features and capabilities of Azure Firewall. The design must scale automatically as traffic grows, and the decision will be reviewed by the network operations team. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7563. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, D
Why: 5.2.7: This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.5, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.
B: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.
C: Correct. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.7: Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub.
D: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
E: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.
F: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 5.2.7, 5.2.1.
Learning point: AZ700-52-Q563: Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected. | Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
Wingtip Services is reviewing an environment where IP allowlists are maintained by external partners. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The landing zone needs centralized stateful inspection and consistent policy for traffic crossing trust boundaries. The network engineer must map requirements to features and capabilities of Azure Firewall; select an appropriate Azure Firewall SKU. The design must scale automatically as traffic grows, and the decision will be reviewed by the Azure landing-zone owner. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7564. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: E, F
Why: 5.2.1: This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 5.2.2: This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
B: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
C: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
D: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 5.2.1, 5.2.2.
E: Correct. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.2: Select an appropriate Azure Firewall SKU.
F: Correct. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 5.2.1: Map requirements to features and capabilities of Azure Firewall.
Learning point: AZ700-52-Q564: Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks. | Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
Popular posts
Recent Posts
