Microsoft AZ-700 Design And Implement Service Endpoints Practice Test

 

AZ-700 skill 4.2 | 30 original questions

This AZ-700 practice set focuses on design and implement service endpoints through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 451

Tailspin Toys is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint; create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7451. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use nonoverlapping CIDR ranges, segment workloads by trust and function, reserve capacity for growth, and validate peering and hybrid address-space conflicts before deployment.
  2. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  3. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  4. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  5. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  6. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Correct answers: B, F

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan and implement network segmentation and address spaces. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.1, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

B: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

C: Not selected. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.4, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

D: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

E: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

F: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

Learning point: AZ700-42-Q451: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required. | Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 452

Humongous Insurance is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7452. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.
  2. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.
  5. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.

Correct answer: C

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

B: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

C: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

D: Not selected. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

E: Not selected. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.1, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

Learning point: AZ700-42-Q452: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 453

Tailspin Toys is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7453. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  2. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.
  3. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  4. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  5. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.

Correct answer: D

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

B: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

C: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

D: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

Learning point: AZ700-42-Q453: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Question 454

Humongous Insurance is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7454. Which recommendation most directly meets the requirement? Select one answer.

  1. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  2. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  3. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  4. Create a Public IP Prefix in the target region so deployments can consume a contiguous set of Azure public IP addresses from a reserved prefix.
  5. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Correct answer: E

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

C: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

D: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

E: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

Learning point: AZ700-42-Q454: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 455

Tailspin Toys is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7455. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  3. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  4. Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
  5. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.

Correct answer: A

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

B: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

C: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

D: Not selected. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.11, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

E: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

Learning point: AZ700-42-Q455: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Question 456

Humongous Insurance is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints; configure service endpoint policies. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7456. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  2. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  3. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  4. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  5. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  6. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.

Correct answers: A, D

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

B: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

C: Not selected. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.4, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

D: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

E: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

F: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

Learning point: AZ700-42-Q456: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet. | Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Question 457

Tailspin Toys is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies; configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7457. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  2. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  3. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  4. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  5. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  6. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.

Correct answers: A, E

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

D: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

E: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

F: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

Learning point: AZ700-42-Q457: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service. | Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 458

Humongous Insurance is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7458. Which recommendation most directly meets the requirement? Select one answer.

  1. Use nonoverlapping CIDR ranges, segment workloads by trust and function, reserve capacity for growth, and validate peering and hybrid address-space conflicts before deployment.
  2. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  3. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  4. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  5. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.

Correct answer: B

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan and implement network segmentation and address spaces. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.1, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

B: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

D: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

E: Not selected. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.1, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

Learning point: AZ700-42-Q458: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 459

Tailspin Toys is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7459. Which recommendation most directly meets the requirement? Select one answer.

  1. Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set.
  2. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Use dedicated subnets when a service requires delegation, special routing, or isolation; share only where supported and where policy and scale requirements are compatible.
  5. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.

Correct answer: C

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

B: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

C: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

D: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

E: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

Learning point: AZ700-42-Q459: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Question 460

Humongous Insurance is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints; configure service endpoint policies. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7460. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  2. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  3. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  4. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  6. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Correct answers: E, F

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

B: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

C: Not selected. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.10, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

D: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

E: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

F: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

Learning point: AZ700-42-Q460: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet. | Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Question 461

Tailspin Toys is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies; configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7461. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  2. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  5. Integrate a supported third-party NVA into the Virtual WAN hub using the vendor-supported deployment and routing model, then validate route propagation and symmetric traffic paths.
  6. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Correct answers: C, D

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.3, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

B: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

C: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

D: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

E: Not selected. This directly satisfies the requirement to integrate a virtual hub with a third-party NVA for cloud connectivity. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.7, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

F: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

Learning point: AZ700-42-Q461: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service. | Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 462

Humongous Insurance is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7462. Which recommendation most directly meets the requirement? Select one answer.

  1. Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
  2. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  3. Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
  4. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  5. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.

Correct answer: D

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.1, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

B: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

C: Not selected. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.10, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

D: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

E: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

Learning point: AZ700-42-Q462: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 463

Tailspin Toys is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7463. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  2. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  3. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  4. Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set.
  5. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Correct answer: E

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

B: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

C: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

D: Not selected. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

E: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

Learning point: AZ700-42-Q463: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Question 464

Humongous Insurance is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7464. Which recommendation most directly meets the requirement? Select one answer.

  1. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  2. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  3. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  4. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  5. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.

Correct answer: A

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

B: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

C: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

D: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

Learning point: AZ700-42-Q464: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 465

Tailspin Toys is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies; configure access to service endpoints; choose when to use a service endpoint. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7465. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  2. Deploy Azure DNS Private Resolver with inbound and outbound endpoints and a forwarding ruleset so hybrid DNS queries can traverse between Azure private zones and on-premises DNS without custom DNS VMs.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.
  5. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  6. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.

Correct answers: A, C, E

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

B: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4, 4.2.1.

C: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4, 4.2.1.

E: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

F: Not selected. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.8, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4, 4.2.1.

Learning point: AZ700-42-Q465: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service. | Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required. | Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Question 466

Humongous Insurance is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints; choose when to use a service endpoint. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7466. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  2. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  5. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  6. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Correct answers: C, E

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 4.2.4, 4.2.1.

B: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 4.2.4, 4.2.1.

C: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

D: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.4, 4.2.1.

E: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

F: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 4.2.4, 4.2.1.

Learning point: AZ700-42-Q466: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required. | Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Question 467

Tailspin Toys is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7467. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.
  2. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  3. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  4. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  5. Use inbound NAT rules when specific frontend ports must map to individual backend instances for management or specialized per-instance access rather than load-balanced service traffic.

Correct answer: B

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.10, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

B: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

C: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

D: Not selected. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

E: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 4.2.1.

Learning point: AZ700-42-Q467: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.

Question 468

Humongous Insurance is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7468. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  2. Choose Azure NAT Gateway when private-subnet workloads need scalable, predictable outbound SNAT and do not require unsolicited inbound connectivity.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  5. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.

Correct answer: C

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

C: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

D: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

Learning point: AZ700-42-Q468: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 469

Tailspin Toys is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies; configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7469. The private endpoint subnet has limited remaining addresses and the service has separate blob and file subresources that are consumed by different application tiers. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  2. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  5. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
  6. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Correct answers: C, F

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

B: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

C: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

D: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

E: Not selected. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.8, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

F: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

Learning point: AZ700-42-Q469: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service. | Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 470

Humongous Insurance is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7470. Which recommendation most directly meets the requirement? Select one answer.

  1. Design Virtual WAN around regional virtual hubs and the required VPN, ExpressRoute, P2S, firewall, and routing services, using hub placement and connectivity intent that match traffic flows and resiliency goals.
  2. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  3. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  4. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  5. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.

Correct answer: D

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design a Virtual WAN architecture, including selecting types and services. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.2, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

B: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

C: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

D: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

E: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

Learning point: AZ700-42-Q470: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 471

Tailspin Toys is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint; create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7471. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  2. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  3. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  4. Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  6. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.

Correct answers: A, E

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

C: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

D: Not selected. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.7, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

E: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

F: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

Learning point: AZ700-42-Q471: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required. | Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 472

Humongous Insurance is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7472. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  2. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  3. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  4. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Correct answer: E

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

B: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

C: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

D: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 4.2.2.

E: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

Learning point: AZ700-42-Q472: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 473

Tailspin Toys is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies; configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7473. The provider service sits behind an internal Standard Load Balancer, while separate business units need independently approved consumer connections and auditable NAT allocation. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Choose Basic only for the limited branch-connectivity scenario; choose Standard when the architecture needs features such as ExpressRoute, P2S, inter-hub transit, Azure Firewall, or broader routing capabilities.
  2. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  5. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  6. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.

Correct answers: B, C

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select a Virtual WAN SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.1, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

B: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

C: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

D: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

E: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

F: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 4.2.3, 4.2.4.

Learning point: AZ700-42-Q473: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service. | Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 474

Humongous Insurance is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7474. Which recommendation most directly meets the requirement? Select one answer.

  1. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  2. Choose Azure NAT Gateway when private-subnet workloads need scalable, predictable outbound SNAT and do not require unsolicited inbound connectivity.
  3. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  4. Deploy the required VPN, ExpressRoute, or P2S gateway into the Virtual WAN hub and size it independently for that connectivity type.
  5. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Correct answer: A

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

C: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

D: Not selected. This directly satisfies the requirement to deploy a gateway into a virtual hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.4.5, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

E: Not selected. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.2.7, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

Learning point: AZ700-42-Q474: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 475

Tailspin Toys is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint; create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7475. The consumer is an on-premises analytics cluster connected by ExpressRoute, and its resolvers currently return the service public address from a legacy forwarder. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  2. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  5. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  6. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Correct answers: C, D

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

B: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

C: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

D: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

E: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

F: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

Learning point: AZ700-42-Q475: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required. | Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 476

Humongous Insurance is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints; configure service endpoint policies. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7476. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.
  2. Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
  3. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  4. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.
  5. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  6. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Correct answers: C, F

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.6, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

B: Not selected. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.12, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

C: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

F: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

Learning point: AZ700-42-Q476: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet. | Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Question 477

Tailspin Toys is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure service endpoint policies. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the platform governance council. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7477. The database team cannot change application connection strings during the migration, but the public service endpoint can remain enabled temporarily under firewall restrictions. Which recommendation most directly meets the requirement? Select one answer.

  1. Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
  2. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  3. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.
  4. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  5. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.

Correct answer: B

Why: 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.3.9, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

B: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

D: Not selected. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.4, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

E: Not selected. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 2.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.3.

Learning point: AZ700-42-Q477: Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Question 478

Humongous Insurance is reviewing an Azure estate that must keep administrative traffic off the public internet. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must configure access to service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the network operations team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7478. A compliance review requires the subnet to reach only the approved storage accounts rather than every account exposed through the same Azure service tag. Which recommendation most directly meets the requirement? Select one answer.

  1. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  2. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  3. Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.
  4. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.
  5. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.

Correct answer: C

Why: 4.2.4: This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

B: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

C: Correct. This directly satisfies the requirement to configure access to service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.4: Configure access to service endpoints.

D: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

E: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 4.2.4.

Learning point: AZ700-42-Q478: Restrict the PaaS resource firewall/network ACL to the approved VNet subnet with the service endpoint enabled and remove broad public access that is no longer required.

Question 479

Tailspin Toys is reviewing a zero-trust network redesign with centralized observability. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must choose when to use a service endpoint; create service endpoints. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the Azure landing-zone owner. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7479. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  2. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  5. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  6. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.

Correct answers: A, C

Why: 4.2.1: This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

C: Correct. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.1: Choose when to use a service endpoint.

D: Not selected. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

E: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

F: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 4.2.1, 4.2.2.

Learning point: AZ700-42-Q479: Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required. | Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Question 480

Humongous Insurance is reviewing a multi-subscription landing zone with centralized networking. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. A supported PaaS service can keep its public endpoint, but access must be restricted to approved Azure subnets. The network engineer must create service endpoints; configure service endpoint policies. The design must provide deterministic egress for partner allowlisting, and the decision will be reviewed by the business continuity lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7480. The PaaS firewall currently permits a broad corporate public IP range, and the network team wants to replace that rule with subnet-scoped authorization. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  2. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.
  3. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  4. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  5. Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.
  6. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.

Correct answers: A, E

Why: 4.2.2: This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 4.2.3: This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.2: Create service endpoints.

B: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

C: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

D: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

E: Correct. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 4.2.3: Configure service endpoint policies.

F: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 4.2.2, 4.2.3.

Learning point: AZ700-42-Q480: Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet. | Apply a service endpoint policy to restrict supported service-endpoint traffic from the subnet to explicitly allowed Azure service resources instead of permitting every resource for that service.

Popular posts

img