Microsoft AZ-700 Design, Implement, And Manage A Site-To-Site VPN Connection Practice Test
AZ-700 skill 2.1 | 32 original questions
This AZ-700 practice set focuses on design, implement, and manage a site-to-site vpn connection through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.
Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability; select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7166. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, E
Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.
B: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.
C: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.
D: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.
E: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.
F: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.
Learning point: AZ700-21-Q166: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention. | Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
Northwind Health is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7167. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
B: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.
C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
D: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
E: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
Learning point: AZ700-21-Q167: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must implement a site-to-site VPN connection; identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7168. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, C
Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.
B: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.
D: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
E: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
F: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
Learning point: AZ700-21-Q168: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings. | Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7169. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.
D: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
E: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
Learning point: AZ700-21-Q169: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway; create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7170. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, D
Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
C: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.
D: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.
E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
F: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
Learning point: AZ700-21-Q170: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection. | Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7171. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.2, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
B: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
D: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.
E: Not selected. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
Learning point: AZ700-21-Q171: Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a virtual network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7172. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
C: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
D: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
E: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.
Learning point: AZ700-21-Q172: Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.
Northwind Health is reviewing a shared-services topology used by several application teams. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must diagnose and resolve virtual network gateway connectivity issues. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7173. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.
B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
C: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
D: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
E: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
Learning point: AZ700-21-Q173: Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement Azure Extended Network; design a site-to-site VPN connection, including for high availability; select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7174. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: A, B, D
Why: 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.
B: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.
C: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.9, 2.1.1, 2.1.2.
D: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.
E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.9, 2.1.1, 2.1.2.
F: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.9, 2.1.1, 2.1.2.
Learning point: AZ700-21-Q174: Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration. | Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention. | Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7175. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
B: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.
C: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
D: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
Learning point: AZ700-21-Q175: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
City Power & Light is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements; implement a site-to-site VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7176. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, B
Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.
B: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.
C: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.
D: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.
E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.
F: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.
Learning point: AZ700-21-Q176: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic. | Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must implement a site-to-site VPN connection; identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7177. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, C
Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
B: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.
C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.
D: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
E: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
F: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.
Learning point: AZ700-21-Q177: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings. | Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7178. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
B: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.5, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.
D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
E: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
Learning point: AZ700-21-Q178: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7179. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5.
B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 2.1.5.
C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.5.
D: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.
E: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 2.1.5.
Learning point: AZ700-21-Q179: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure an IPsec/Internet Key Exchange (IKE) policy; create and configure a virtual network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7180. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, E
Why: 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.
B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.
C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.
D: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.
E: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.
F: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.
Learning point: AZ700-21-Q180: Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers. | Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.
Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a virtual network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7181. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
B: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.7.
E: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.
Learning point: AZ700-21-Q181: Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.
City Power & Light is reviewing a shared-services topology used by several application teams. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must diagnose and resolve virtual network gateway connectivity issues. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7182. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.
B: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
C: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
E: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.1.8.
Learning point: AZ700-21-Q182: Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Azure Extended Network. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7183. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
B: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.
C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
D: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
E: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
Learning point: AZ700-21-Q183: Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7184. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
B: Not selected. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
C: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.
D: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
Learning point: AZ700-21-Q184: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
Northwind Health is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7185. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
D: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.
E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
Learning point: AZ700-21-Q185: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement a site-to-site VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7186. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
B: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
D: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
E: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.
Learning point: AZ700-21-Q186: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7187. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.
B: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
C: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
D: Not selected. This directly satisfies the requirement to create and configure explicit outbound rules, including source network address translation (SNAT). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.11, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
Learning point: AZ700-21-Q187: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway; create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7188. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, D
Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
B: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.
C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
D: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.
E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
F: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
Learning point: AZ700-21-Q188: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection. | Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7189. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
B: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.
C: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
D: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
E: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.6.
Learning point: AZ700-21-Q189: Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must create and configure a virtual network gateway; diagnose and resolve virtual network gateway connectivity issues. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7190. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, C
Why: 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.
B: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.
C: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.
D: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.
E: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.
F: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.
Learning point: AZ700-21-Q190: Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration. | Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
Northwind Health is reviewing a shared-services topology used by several application teams. Operators need evidence that identifies the failing hop or policy before they make a production network change. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must diagnose and resolve virtual network gateway connectivity issues; implement Azure Extended Network. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7191. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, E
Why: 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.
B: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.
C: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.
D: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.
E: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.
F: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.
Learning point: AZ700-21-Q191: Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway. | Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Azure Extended Network. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7192. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
C: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.
D: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.9.
Learning point: AZ700-21-Q192: Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7193. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
B: Not selected. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
D: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.
E: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.
Learning point: AZ700-21-Q193: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
City Power & Light is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7194. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
B: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
C: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
D: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2.
E: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.
Learning point: AZ700-21-Q194: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement a site-to-site VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7195. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
C: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
D: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
E: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.3.
Learning point: AZ700-21-Q195: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7196. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
B: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.
C: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
E: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.
Learning point: AZ700-21-Q196: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway; create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7197. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, E
Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
B: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
D: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.
E: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.
F: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.
Learning point: AZ700-21-Q197: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection. | Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
Popular posts
Recent Posts
