Microsoft AZ-700 Design, Implement, And Manage A Point-To-Site VPN Connection Practice Test

 

AZ-700 skill 2.2 | 32 original questions

This AZ-700 practice set focuses on design, implement, and manage a point-to-site vpn connection through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 198

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7198. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  2. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  3. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.
  4. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  5. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.

Correct answer: C

Why: 2.2.1: This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

B: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

C: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.1: Select an appropriate virtual network gateway SKU for point-to-site VPN requirements.

D: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

Learning point: AZ700-22-Q198: Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.

Question 199

Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select and configure a tunnel type. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7199. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose Azure NAT Gateway when private-subnet workloads need scalable, predictable outbound SNAT and do not require unsolicited inbound connectivity.
  2. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  3. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  4. Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.
  5. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.

Correct answer: D

Why: 2.2.2: This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

B: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

C: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

D: Correct. This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.2: Select and configure a tunnel type.

E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

Learning point: AZ700-22-Q199: Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.

Question 200

City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select an appropriate authentication method. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7200. Which recommendation most directly meets the requirement? Select one answer.

  1. Create a Standard public IP address with the required allocation, zone, and routing preference settings, then protect and monitor the resource as part of the workload design.
  2. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  3. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  4. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  5. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Correct answer: E

Why: 2.2.3: This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

B: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

E: Correct. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.3: Select an appropriate authentication method.

Learning point: AZ700-22-Q200: Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Question 201

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure RADIUS authentication; configure authentication by using Microsoft Entra ID. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7201. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Create the NSG with a clear workload scope and policy ownership, then add only the required rules instead of duplicating default platform rules.
  2. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  3. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  4. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  5. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
  6. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.

Correct answers: C, F

Why: 2.2.4: This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

C: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

E: Not selected. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.2, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

F: Correct. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.4: Configure RADIUS authentication.

Learning point: AZ700-22-Q201: Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service. | Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.

Question 202

City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must configure authentication by using Microsoft Entra ID; implement a VPN client configuration file; diagnose and resolve client-side and authentication issues. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7202. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  2. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  3. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  4. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  5. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  6. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Correct answers: B, C, F

Why: 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.7: This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6, 2.2.7.

B: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

C: Correct. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.7: Diagnose and resolve client-side and authentication issues.

D: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6, 2.2.7.

E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6, 2.2.7.

F: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

Learning point: AZ700-22-Q202: Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings. | Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata. | Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Question 203

Northwind Health is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement a VPN client configuration file. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7203. Which recommendation most directly meets the requirement? Select one answer.

  1. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  2. Use Azure Load Balancer for high-performance Layer 4 TCP/UDP distribution with health probes and frontend/backend rules, not for URL-path or host-header routing.
  3. Create the Front Door profile, endpoint, origin group, origins, health probes, and routes so host/path matching and origin priorities implement the required global traffic flow.
  4. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  5. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.

Correct answer: A

Why: 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

C: Not selected. This directly satisfies the requirement to configure an Azure Front Door, including routing, origins, and endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.4, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

E: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

Learning point: AZ700-22-Q203: Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Question 204

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Operators need evidence that identifies the failing hop or policy before they make a production network change. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must diagnose and resolve client-side and authentication issues; specify Azure requirements for Always On VPN. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7204. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.
  2. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.
  3. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  4. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  6. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Correct answers: B, F

Why: 2.2.7: This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.8: This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.2.7, 2.2.8.

B: Correct. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.8: Specify Azure requirements for Always On VPN.

C: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 2.2.7, 2.2.8.

D: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.2.7, 2.2.8.

E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.2.7, 2.2.8.

F: Correct. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.7: Diagnose and resolve client-side and authentication issues.

Learning point: AZ700-22-Q204: Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related. | For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.

Question 205

Northwind Health is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must specify Azure requirements for Always On VPN; specify Azure requirements for Azure Network Adapter. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7205. Which TWO recommendations should be implemented together? Select TWO answers.

  1. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.
  2. Create the appropriate Azure DNS zones and record sets, separating public authoritative records from private records and applying the required TTL and VNet-link configuration.
  3. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  4. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  5. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.
  6. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.

Correct answers: A, E

Why: 2.2.8: This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.9: This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.8: Specify Azure requirements for Always On VPN.

B: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 2.2.8, 2.2.9.

C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.2.8, 2.2.9.

D: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.2.8, 2.2.9.

E: Correct. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.9: Specify Azure requirements for Azure Network Adapter.

F: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 2.2.8, 2.2.9.

Learning point: AZ700-22-Q205: For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern. | Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.

Question 206

City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must specify Azure requirements for Azure Network Adapter. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7206. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  2. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.
  3. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.
  4. Place WAF on the Application Gateway or Front Door entry point that sees the protected HTTP(S) traffic, choose the appropriate policy scope, and plan exclusions and logging before enforcing blocks.
  5. Create a Public IP Prefix in the target region so deployments can consume a contiguous set of Azure public IP addresses from a reserved prefix.

Correct answer: B

Why: 2.2.9: This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

B: Correct. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.9: Specify Azure requirements for Azure Network Adapter.

C: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

D: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

E: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

Learning point: AZ700-22-Q206: Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.

Question 207

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7207. Which recommendation most directly meets the requirement? Select one answer.

  1. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  2. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  3. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.
  4. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  5. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.

Correct answer: C

Why: 2.2.1: This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

B: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

C: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.1: Select an appropriate virtual network gateway SKU for point-to-site VPN requirements.

D: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

E: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

Learning point: AZ700-22-Q207: Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.

Question 208

City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select and configure a tunnel type. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7208. Which recommendation most directly meets the requirement? Select one answer.

  1. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  2. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  3. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  4. Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.
  5. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.

Correct answer: D

Why: 2.2.2: This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.9, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

B: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

C: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

D: Correct. This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.2: Select and configure a tunnel type.

E: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

Learning point: AZ700-22-Q208: Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.

Question 209

Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select an appropriate authentication method. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7209. Which recommendation most directly meets the requirement? Select one answer.

  1. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.
  2. Use Azure Firewall Manager to create hierarchical Firewall Policies with shared base policy and child policies so multiple firewalls receive centrally governed rules without duplicating configuration.
  3. Reserve service-appropriate subnets with the required sizes and separation for gateways, private endpoints, firewalls, Application Gateway, Bastion, and VNet-integrated services.
  4. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  5. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Correct answer: E

Why: 2.2.3: This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

B: Not selected. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.6, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

C: Not selected. This directly satisfies the requirement to plan and configure subnetting for services, including virtual network gateways, private endpoints, service endpoints, firewalls, application gateways, VNet-integrated platform services, and Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.3, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

D: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 2.2.3.

E: Correct. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.3: Select an appropriate authentication method.

Learning point: AZ700-22-Q209: Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Question 210

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure RADIUS authentication. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7210. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  2. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  3. Create a Standard public IP address with the required allocation, zone, and routing preference settings, then protect and monitor the resource as part of the workload design.
  4. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  5. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Correct answer: A

Why: 2.2.4: This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.4: Configure RADIUS authentication.

B: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

C: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

D: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

E: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

Learning point: AZ700-22-Q210: Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.

Question 211

Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must configure authentication by using Microsoft Entra ID; implement a VPN client configuration file. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7211. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  2. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  3. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.
  4. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  5. Use Azure Firewall when the design needs centralized stateful L3-L7 filtering, threat intelligence, DNAT/SNAT, application/network rules, and managed scaling across Azure networks.
  6. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.

Correct answers: A, F

Why: 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

C: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

D: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Firewall. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.1, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

F: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

Learning point: AZ700-22-Q211: Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings. | Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Question 212

City Power & Light is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement a VPN client configuration file. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7212. Which recommendation most directly meets the requirement? Select one answer.

  1. Create the Standard Load Balancer with the required frontend, backend pool, health probe, and load-balancing or NAT rules, then validate NSG and return-path behavior.
  2. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  3. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  4. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  5. Reserve service-appropriate subnets with the required sizes and separation for gateways, private endpoints, firewalls, Application Gateway, Bastion, and VNet-integrated services.

Correct answer: B

Why: 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

B: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

C: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

E: Not selected. This directly satisfies the requirement to plan and configure subnetting for services, including virtual network gateways, private endpoints, service endpoints, firewalls, application gateways, VNet-integrated platform services, and Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.3, but it does not directly satisfy the scenario requirement mapped to 2.2.6.

Learning point: AZ700-22-Q212: Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Question 213

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must diagnose and resolve client-side and authentication issues. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7213. Which recommendation most directly meets the requirement? Select one answer.

  1. Convert or deploy the Virtual WAN hub as a secured virtual hub with Azure Firewall and use routing intent or hub route tables so the required internet and private traffic is inspected.
  2. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  3. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  4. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  5. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.

Correct answer: C

Why: 2.2.7: This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.7, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

B: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

C: Correct. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.7: Diagnose and resolve client-side and authentication issues.

D: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

E: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

Learning point: AZ700-22-Q213: Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Question 214

City Power & Light is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must specify Azure requirements for Always On VPN. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7214. Which recommendation most directly meets the requirement? Select one answer.

  1. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  2. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  3. Implement Front Door rules with explicit match conditions and actions for header changes, URL rewrites, or redirects, and verify rule-set ordering to avoid unexpected routing behavior.
  4. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.
  5. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.

Correct answer: D

Why: 2.2.8: This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

B: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

C: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

D: Correct. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.8: Specify Azure requirements for Always On VPN.

E: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

Learning point: AZ700-22-Q214: For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.

Question 215

Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must specify Azure requirements for Azure Network Adapter. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7215. Which recommendation most directly meets the requirement? Select one answer.

  1. Create a route table with UDRs for the required prefixes and next-hop types, avoid routes that cause loops or asymmetric paths, and validate the resulting effective routes.
  2. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  3. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  4. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  5. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.

Correct answer: E

Why: 2.2.9: This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

B: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

C: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

D: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 2.2.9.

E: Correct. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.9: Specify Azure requirements for Azure Network Adapter.

Learning point: AZ700-22-Q215: Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.

Question 216

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select an appropriate virtual network gateway SKU for point-to-site VPN requirements; select and configure a tunnel type. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7216. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.
  2. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  3. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  4. Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.
  5. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.
  6. Create the NAT Gateway with a public IP or prefix and associate it to the required subnets so outbound flows use the managed SNAT path.

Correct answers: A, D

Why: 2.2.1: This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.2: This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.1: Select an appropriate virtual network gateway SKU for point-to-site VPN requirements.

B: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 2.2.1, 2.2.2.

C: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 2.2.1, 2.2.2.

D: Correct. This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.2: Select and configure a tunnel type.

E: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.2.1, 2.2.2.

F: Not selected. This directly satisfies the requirement to implement Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.10, but it does not directly satisfy the scenario requirement mapped to 2.2.1, 2.2.2.

Learning point: AZ700-22-Q216: Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features. | Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.

Question 217

Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select and configure a tunnel type. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7217. Which recommendation most directly meets the requirement? Select one answer.

  1. Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.
  2. Avoid broad internet RDP/SSH exposure; use Azure Bastion or a tightly scoped management path and restrict NSG management ports to the approved source and required time window.
  3. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  4. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  5. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.

Correct answer: A

Why: 2.2.2: This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.2: Select and configure a tunnel type.

B: Not selected. This directly satisfies the requirement to configure an NSG for remote server administration, including Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.9, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

C: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

D: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.2.

Learning point: AZ700-22-Q217: Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.

Question 218

City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select an appropriate authentication method; configure RADIUS authentication. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7218. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  2. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  3. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.
  4. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  5. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.
  6. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Correct answers: B, F

Why: 2.2.3: This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.4: This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4.

B: Correct. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.4: Configure RADIUS authentication.

C: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4.

D: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4.

F: Correct. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.3: Select an appropriate authentication method.

Learning point: AZ700-22-Q218: Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements. | Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.

Question 219

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure RADIUS authentication. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7219. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  2. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  3. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  4. Create a private endpoint in the selected subnet for the specific service subresource, approve the connection where required, and validate the assigned private IP.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Correct answer: B

Why: 2.2.4: This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

B: Correct. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.4: Configure RADIUS authentication.

C: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

D: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.2.4.

Learning point: AZ700-22-Q219: Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.

Question 220

City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must configure authentication by using Microsoft Entra ID; implement a VPN client configuration file. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7220. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  2. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  3. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  4. Reserve service-appropriate subnets with the required sizes and separation for gateways, private endpoints, firewalls, Application Gateway, Bastion, and VNet-integrated services.
  5. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  6. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.

Correct answers: B, F

Why: 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

B: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

C: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

D: Not selected. This directly satisfies the requirement to plan and configure subnetting for services, including virtual network gateways, private endpoints, service endpoints, firewalls, application gateways, VNet-integrated platform services, and Azure Bastion. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.3, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

E: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

F: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

Learning point: AZ700-22-Q220: Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings. | Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

Question 221

Northwind Health is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must implement a VPN client configuration file; diagnose and resolve client-side and authentication issues. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7221. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  2. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.
  3. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  4. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  5. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.
  6. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Correct answers: A, D

Why: 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.7: This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

B: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 2.2.6, 2.2.7.

C: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.2.6, 2.2.7.

D: Correct. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.7: Diagnose and resolve client-side and authentication issues.

E: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.2.6, 2.2.7.

F: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.2.6, 2.2.7.

Learning point: AZ700-22-Q221: Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata. | Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Question 222

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must diagnose and resolve client-side and authentication issues. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7222. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  2. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  3. Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.
  4. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  5. Create a backend pool containing the intended IPs, FQDNs, VMSS, or supported targets, keeping host-name and DNS behavior consistent with backend HTTP settings.

Correct answer: C

Why: 2.2.7: This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

B: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

C: Correct. This directly satisfies the requirement to diagnose and resolve client-side and authentication issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.7: Diagnose and resolve client-side and authentication issues.

D: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

E: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 2.2.7.

Learning point: AZ700-22-Q222: Check the client logs, profile version, tunnel protocol, certificate or Entra/RADIUS state, DNS/routes, and gateway diagnostics to isolate whether the failure is local, identity-related, or network-related.

Question 223

Northwind Health is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must specify Azure requirements for Always On VPN. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7223. Which recommendation most directly meets the requirement? Select one answer.

  1. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  2. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  3. Add the relevant VM NIC IP configuration to the ASG so NSG rules that reference the ASG apply to that workload role.
  4. For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.
  5. Enable virtual network flow logs for the required scope and send the records to the approved storage or analytics destination with retention that supports operations and investigations.

Correct answer: D

Why: 2.2.8: This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

B: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

C: Not selected. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.4, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

D: Correct. This directly satisfies the requirement to specify Azure requirements for Always On VPN. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.8: Specify Azure requirements for Always On VPN.

E: Not selected. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.6, but it does not directly satisfy the scenario requirement mapped to 2.2.8.

Learning point: AZ700-22-Q223: For Always On VPN, ensure Azure provides the required VPN gateway capacity, routes, authentication reachability, DNS, and supported tunnel configuration while device/user tunnel policy remains a Windows client design concern.

Question 224

City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must specify Azure requirements for Azure Network Adapter; select an appropriate virtual network gateway SKU for point-to-site VPN requirements; select and configure a tunnel type. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7224. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.
  2. Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity.
  3. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.
  4. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  5. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.
  6. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.

Correct answers: A, B, C

Why: 2.2.9: This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.1: This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.2: This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.2: Select and configure a tunnel type.

B: Correct. This directly satisfies the requirement to specify Azure requirements for Azure Network Adapter. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.9: Specify Azure requirements for Azure Network Adapter.

C: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.1: Select an appropriate virtual network gateway SKU for point-to-site VPN requirements.

D: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.2.9, 2.2.1, 2.2.2.

E: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 2.2.9, 2.2.1, 2.2.2.

F: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.2.9, 2.2.1, 2.2.2.

Learning point: AZ700-22-Q224: Meet Azure Network Adapter prerequisites for Windows Admin Center, Azure connectivity, supported gateway configuration, and local server networking before using the feature for point-to-site connectivity. | Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features. | Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.

Question 225

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7225. Which recommendation most directly meets the requirement? Select one answer.

  1. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  2. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  3. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  4. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  5. Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.

Correct answer: E

Why: 2.2.1: This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

B: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.2.1.

E: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway SKU for point-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.1: Select an appropriate virtual network gateway SKU for point-to-site VPN requirements.

Learning point: AZ700-22-Q225: Choose a VPN gateway SKU that supports the required point-to-site user scale, aggregate throughput, zone resiliency, and protocol/authentication features.

Question 226

City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select and configure a tunnel type; select an appropriate authentication method. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the hybrid connectivity team. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7226. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  2. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  3. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  4. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  5. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  6. Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile.

Correct answers: A, F

Why: 2.2.2: This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.3: This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.3: Select an appropriate authentication method.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.2.2, 2.2.3.

C: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.2, 2.2.3.

D: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 2.2.2, 2.2.3.

E: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.2, 2.2.3.

F: Correct. This directly satisfies the requirement to select and configure a tunnel type. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.2: Select and configure a tunnel type.

Learning point: AZ700-22-Q226: Select OpenVPN, IKEv2, or the supported combination based on client platforms, authentication, firewall traversal, and policy requirements, then publish a matching client profile. | Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.

Question 227

Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must select an appropriate authentication method; configure RADIUS authentication; configure authentication by using Microsoft Entra ID. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the application delivery team. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7227. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements.
  2. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  3. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  4. Use Application Gateway for regional Layer 7 HTTP(S) delivery with host/path routing, TLS termination, autoscale, and optional WAF in front of private or public backends.
  5. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  6. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.

Correct answers: A, B, E

Why: 2.2.3: This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.4: This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select an appropriate authentication method. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.3: Select an appropriate authentication method.

B: Correct. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.4: Configure RADIUS authentication.

C: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4, 2.2.5.

D: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.1, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4, 2.2.5.

E: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

F: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 2.2.3, 2.2.4, 2.2.5.

Learning point: AZ700-22-Q227: Choose certificate, RADIUS, or Microsoft Entra ID authentication based on identity source, client platform, MFA/Conditional Access needs, and operational requirements. | Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service. | Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.

Question 228

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure RADIUS authentication; configure authentication by using Microsoft Entra ID. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the security engineering lead. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7228. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service.
  2. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  3. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.
  4. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  5. Create a virtual network link from the Private DNS zone to the required VNet and enable auto-registration only when that VNet should register VM host records.
  6. Create a Public IP Prefix in the target region so deployments can consume a contiguous set of Azure public IP addresses from a reserved prefix.

Correct answers: A, D

Why: 2.2.4: This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure RADIUS authentication. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.4: Configure RADIUS authentication.

B: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

C: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

D: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

E: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

F: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.2.4, 2.2.5.

Learning point: AZ700-22-Q228: Configure the P2S gateway to use the reachable RADIUS server and shared secret, and ensure routing and NSG/firewall rules allow RADIUS traffic between Azure and the identity service. | Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.

Question 229

Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must configure authentication by using Microsoft Entra ID; implement a VPN client configuration file. The design must use managed Azure capabilities instead of custom appliances where practical, and the decision will be reviewed by the cloud architecture board. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7229. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings.
  2. Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.
  3. Choose Azure Load Balancer when the requirement is regional or cross-region Layer 4 load distribution for TCP/UDP services and application-layer inspection is unnecessary.
  4. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  5. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  6. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.

Correct answers: A, B

Why: 2.2.5: This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.2.6: This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to configure authentication by using Microsoft Entra ID. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.5: Configure authentication by using Microsoft Entra ID.

B: Correct. This directly satisfies the requirement to implement a VPN client configuration file. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.2.6: Implement a VPN client configuration file.

C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

D: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

E: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

F: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.2.5, 2.2.6.

Learning point: AZ700-22-Q229: Configure P2S OpenVPN with Microsoft Entra ID authentication, authorize the Azure VPN application as required, and distribute a client profile that uses the tenant and audience settings. | Generate and distribute a current P2S VPN client configuration package after gateway or authentication changes so clients receive the correct routes, endpoints, and authentication metadata.

img