Microsoft AZ-700 Design, Implement, And Manage A Site-To-Site VPN Connection Practice Test

 

AZ-700 skill 2.1 | 32 original questions

This AZ-700 practice set focuses on design, implement, and manage a site-to-site vpn connection through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.

Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.

Question 166

City Power & Light is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability; select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7166. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  2. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  3. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.
  4. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
  5. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  6. Configure basic or path-based routing rules that connect the intended listener to the correct backend pool and HTTP settings, with redirects or rewrites only where required.

Correct answers: D, E

Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.

B: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.

C: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.

D: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.

E: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.

F: Not selected. This directly satisfies the requirement to configure routing rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.7, but it does not directly satisfy the scenario requirement mapped to 2.1.1, 2.1.2.

Learning point: AZ700-21-Q166: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention. | Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Question 167

Northwind Health is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7167. Which recommendation most directly meets the requirement? Select one answer.

  1. Delegate the target subnet to the required Azure platform service and ensure the subnet meets that service’s delegation and coexistence constraints.
  2. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
  3. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  4. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  5. Create a WAF policy with the intended managed rules, custom rules, exclusions, mode, and logging configuration so protection is versioned and reusable instead of embedded ad hoc in a gateway.

Correct answer: B

Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

B: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.

C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

D: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

E: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

Learning point: AZ700-21-Q167: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Question 168

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must implement a site-to-site VPN connection; identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7168. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  2. Inspect effective routes and next-hop results in Network Watcher, then verify peering, BGP advertisements, UDR precedence, and return paths before changing the design.
  3. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  4. Delegate the target subnet to the required Azure platform service and ensure the subnet meets that service’s delegation and coexistence constraints.
  5. Terminate or re-encrypt TLS on Application Gateway using certificates from the approved source, enforce the required TLS policy, and validate end-to-end certificate trust when HTTPS continues to the backend.
  6. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.

Correct answers: A, C

Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.

B: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.

D: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

E: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

F: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

Learning point: AZ700-21-Q168: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings. | Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Question 169

Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7169. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  2. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  3. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  4. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  5. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.

Correct answer: C

Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

B: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.

D: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

E: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

Learning point: AZ700-21-Q169: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Question 170

City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway; create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7170. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Analyze flow-log tuples and traffic analytics to determine source/destination, ports, direction, allow/deny result, and traffic volume before changing NSG policy.
  2. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  3. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  4. Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection.
  5. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.
  6. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.

Correct answers: C, D

Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

C: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.

D: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.

E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

F: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

Learning point: AZ700-21-Q170: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection. | Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.

Question 171

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7171. Which recommendation most directly meets the requirement? Select one answer.

  1. Associate the NSG at the subnet for consistent workload policy, at the NIC for justified host-specific policy, or at both only when the combined effective rules are intentionally understood.
  2. Configure the load-balancing rule with the correct frontend, backend pool, protocol, ports, health probe, session persistence, and floating-IP settings for the workload.
  3. Provide on-premises clients a private routed path to the consumer VNet and hybrid DNS resolution for the private endpoint, rather than trying to route directly to the provider-side Private Link Service NAT addresses.
  4. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  5. Use Azure Virtual Network Manager security admin configurations for centrally enforced baseline rules across network groups, while leaving NSGs for workload-specific controls.

Correct answer: D

Why: 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.2, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

B: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

C: Not selected. This directly satisfies the requirement to integrate a Private Link service with on-premises clients. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.6, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

D: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.

E: Not selected. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

Learning point: AZ700-21-Q171: Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.

Question 172

City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a virtual network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7172. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  2. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  3. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  4. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  5. Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.

Correct answer: E

Why: 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

C: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

D: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

E: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.

Learning point: AZ700-21-Q172: Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.

Question 173

Northwind Health is reviewing a shared-services topology used by several application teams. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must diagnose and resolve virtual network gateway connectivity issues. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7173. Which recommendation most directly meets the requirement? Select one answer.

  1. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
  2. Associate the route table with the intended subnet so its UDRs participate in effective routing for resources in that subnet.
  3. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  4. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  5. Attach a Front Door WAF policy with the required managed rule set and tuned custom rules to the relevant Front Door domains/routes, using exclusions only for well-understood false positives.

Correct answer: A

Why: 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.

B: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

C: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

D: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

E: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

Learning point: AZ700-21-Q173: Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.

Question 174

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement Azure Extended Network; design a site-to-site VPN connection, including for high availability; select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7174. Which THREE recommendations should be implemented together? Select THREE answers.

  1. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  2. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  3. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  4. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  6. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.

Correct answers: A, B, D

Why: 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.

B: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.

C: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.9, 2.1.1, 2.1.2.

D: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.

E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.9, 2.1.1, 2.1.2.

F: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.9, 2.1.1, 2.1.2.

Learning point: AZ700-21-Q174: Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration. | Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention. | Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Question 175

Northwind Health is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7175. Which recommendation most directly meets the requirement? Select one answer.

  1. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  2. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  3. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.
  4. Create the appropriate Azure DNS zones and record sets, separating public authoritative records from private records and applying the required TTL and VNet-link configuration.
  5. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.

Correct answer: B

Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

B: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.

C: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

D: Not selected. This directly satisfies the requirement to configure public and private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

E: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

Learning point: AZ700-21-Q175: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.

Question 176

City Power & Light is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements; implement a site-to-site VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7176. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
  2. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  3. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.
  4. Enable Front Door caching only for cacheable content, set query-string and compression behavior intentionally, and use cache-control/rules so personalized or sensitive responses are not cached.
  5. Use a regional load balancer for backends in one Azure region and a cross-region load balancer when a global Layer 4 entry point must distribute to regional load balancers.
  6. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.

Correct answers: A, B

Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.

B: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.

C: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.

D: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.

E: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.

F: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.2, 2.1.3.

Learning point: AZ700-21-Q176: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic. | Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.

Question 177

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must implement a site-to-site VPN connection; identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7177. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.
  2. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  3. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  4. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.
  5. Use a public frontend when clients arrive from the internet and an internal frontend when the service should be reachable only through private networking.
  6. Configure backend HTTP settings for protocol, port, host-name handling, cookie affinity, timeout, connection draining, and trusted backend certificates as required.

Correct answers: B, C

Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

B: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.

C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.

D: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

E: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

F: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.1.3, 2.1.4.

Learning point: AZ700-21-Q177: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings. | Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Question 178

City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7178. Which recommendation most directly meets the requirement? Select one answer.

  1. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  2. Configure the Application Gateway WAF policy with the required managed OWASP rule set, custom rules, exclusions, and policy settings, then associate it at the intended gateway/listener/path scope.
  3. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  4. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  5. Use Front Door’s edge ingress and Microsoft global network path to accelerate HTTP(S) traffic, keeping origins healthy and appropriately placed rather than forcing clients to connect directly to distant regions.

Correct answer: C

Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

B: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.5, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

C: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.

D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

E: Not selected. This directly satisfies the requirement to configure traffic acceleration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

Learning point: AZ700-21-Q178: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Question 179

Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7179. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  2. Use Azure Load Balancer for high-performance Layer 4 TCP/UDP distribution with health probes and frontend/backend rules, not for URL-path or host-header routing.
  3. Use Azure Private DNS zones for internal namespaces and private-endpoint records, planning VNet links so only the required networks can resolve those names.
  4. Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection.
  5. Use Defender for Cloud attack path analysis to identify exploitable chains that reach high-value assets and remediate the choke points that reduce the greatest real attack exposure.

Correct answer: D

Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5.

B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 2.1.5.

C: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.5.

D: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.

E: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 2.1.5.

Learning point: AZ700-21-Q179: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection.

Question 180

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure an IPsec/Internet Key Exchange (IKE) policy; create and configure a virtual network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7180. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  2. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  3. Choose Azure Load Balancer when the requirement is regional or cross-region Layer 4 load distribution for TCP/UDP services and application-layer inspection is unnecessary.
  4. Use Cloud Security Explorer to query the cloud security graph for network resources and relationships, then pivot from the results into the relevant posture or exposure investigation.
  5. Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.
  6. Plan private endpoints per service and region, including subnet capacity, DNS zone integration, approval workflow, network policies, and the effect on existing public access.

Correct answers: A, E

Why: 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.

B: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.

C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.

D: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.

E: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.

F: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.1.6, 2.1.7.

Learning point: AZ700-21-Q180: Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers. | Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.

Question 181

Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a virtual network gateway. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7181. Which recommendation most directly meets the requirement? Select one answer.

  1. Design Azure Firewall in the required hub or secured virtual hub with adequate subnet/addressing, routing symmetry, zones where supported, DNS/proxy choices, and a policy hierarchy that separates shared and local rules.
  2. Deploy Azure DNS Private Resolver with inbound and outbound endpoints and a forwarding ruleset so hybrid DNS queries can traverse between Azure private zones and on-premises DNS without custom DNS VMs.
  3. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  4. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  5. Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.

Correct answer: E

Why: 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

B: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.7.

E: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.

Learning point: AZ700-21-Q181: Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.

Question 182

City Power & Light is reviewing a shared-services topology used by several application teams. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must diagnose and resolve virtual network gateway connectivity issues. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7182. Which recommendation most directly meets the requirement? Select one answer.

  1. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
  2. Associate the public IP to the supported frontend resource that actually needs internet reachability, such as a load balancer frontend, gateway, firewall, or NIC, instead of assigning public IPs broadly.
  3. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  4. Use Front Door Premium Private Link to reach the supported origin privately, approve the private endpoint connection, and restrict the origin so it does not also accept unintended public traffic.
  5. Create a Public IP Prefix in the target region so deployments can consume a contiguous set of Azure public IP addresses from a reserved prefix.

Correct answer: A

Why: 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.

B: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

C: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

D: Not selected. This directly satisfies the requirement to secure an origin by using Azure Private Link in Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.9, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

E: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.1.8.

Learning point: AZ700-21-Q182: Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.

Question 183

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Azure Extended Network. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7183. Which recommendation most directly meets the requirement? Select one answer.

  1. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.
  2. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Use a service endpoint when a supported Azure PaaS resource can remain on its public endpoint but must recognize and restrict access to selected VNet subnets; use Private Link when a private IP endpoint is required.
  5. Use Application Gateway rewrite rule sets to modify supported request or response headers and URLs under explicit conditions instead of changing application code for simple gateway-layer transformations.

Correct answer: B

Why: 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

B: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.

C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

D: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

E: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

Learning point: AZ700-21-Q183: Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.

Question 184

City Power & Light is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7184. Which recommendation most directly meets the requirement? Select one answer.

  1. Create an ASG to represent an application role so NSG rules can reference logical workload groups instead of maintaining IP-address lists.
  2. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  3. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  4. Place VNets in Azure Virtual Network Manager network groups and deploy a connectivity configuration so hub-and-spoke or mesh connectivity is centrally governed at scale.
  5. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.

Correct answer: C

Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

B: Not selected. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

C: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.

D: Not selected. This directly satisfies the requirement to implement and manage virtual network connectivity by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

Learning point: AZ700-21-Q184: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.

Question 185

Northwind Health is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7185. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure rule collection groups and network, application, or DNAT rules with least privilege, explicit priorities, and FQDN/service-tag use where appropriate, then validate logs for unintended denies.
  2. Configure a custom health probe that targets a reliable application health endpoint with the right host, protocol, path, interval, timeout, and healthy-status criteria.
  3. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.
  4. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.
  5. Publish the producer service through a Private Link Service behind a Standard internal Load Balancer, configure NAT IPs and visibility/approval, and onboard consumer private endpoints.

Correct answer: D

Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

B: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

D: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.

E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

Learning point: AZ700-21-Q185: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Question 186

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement a site-to-site VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7186. Which recommendation most directly meets the requirement? Select one answer.

  1. Use inbound NAT rules when specific frontend ports must map to individual backend instances for management or specialized per-instance access rather than load-balanced service traffic.
  2. Create the Standard Load Balancer with the required frontend, backend pool, health probe, and load-balancing or NAT rules, then validate NSG and return-path behavior.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  5. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.

Correct answer: E

Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

B: Not selected. This directly satisfies the requirement to create and configure an Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.6, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

D: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

E: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.

Learning point: AZ700-21-Q186: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.

Question 187

Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7187. Which recommendation most directly meets the requirement? Select one answer.

  1. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  2. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  3. Use dedicated subnets when a service requires delegation, special routing, or isolation; share only where supported and where policy and scale requirements are compatible.
  4. Configure explicit outbound rules or, preferably where appropriate, a NAT Gateway so SNAT capacity and outbound public addresses are deterministic rather than relying on implicit behavior.
  5. Enable the required service endpoint on the client subnet and then configure the target PaaS resource network rules to permit that subnet.

Correct answer: A

Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.

B: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

C: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

D: Not selected. This directly satisfies the requirement to create and configure explicit outbound rules, including source network address translation (SNAT). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.11, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

E: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

Learning point: AZ700-21-Q187: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Question 188

City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway; create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7188. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Choose Application Gateway when the application needs regional Layer 7 routing, TLS offload, cookie affinity, redirects/rewrites, or WAF close to Azure backends.
  2. Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection.
  3. Protect the required VNets and public IP workloads with Azure DDoS Network Protection, configure monitoring and alerts, and integrate DDoS telemetry into incident response.
  4. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  5. Use Azure Front Door for global Layer 7 anycast entry, health-based routing, acceleration, TLS, caching, rules, and optional WAF across geographically distributed origins.
  6. Use autoscale for variable or unpredictable traffic and configure sensible minimum/maximum capacity; use fixed/manual capacity only when load is stable and explicitly controlled.

Correct answers: B, D

Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

B: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.

C: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

D: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.

E: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

F: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

Learning point: AZ700-21-Q188: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection. | Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.

Question 189

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7189. Which recommendation most directly meets the requirement? Select one answer.

  1. Use a Public IP Prefix when you need predictable contiguous Azure public addresses for scaling, partner allowlisting, or simplified public-IP lifecycle management.
  2. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  3. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.
  4. Use Gateway Load Balancer to insert and scale compatible NVAs transparently in the traffic path through service chaining with a consumer frontend.
  5. Use a hub-and-spoke design with peering options such as forwarded traffic and gateway transit so spokes can consume shared gateways or NVAs without creating unsupported transitive peering assumptions.

Correct answer: B

Why: 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

B: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.

C: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

D: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

E: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.6.

Learning point: AZ700-21-Q189: Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.

Question 190

City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Operators need evidence that identifies the failing hop or policy before they make a production network change. The network engineer must create and configure a virtual network gateway; diagnose and resolve virtual network gateway connectivity issues. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7190. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration.
  2. Use Azure Monitor network insights, metrics, alerts, and workbooks to correlate health and performance across network resources and identify degradations over time.
  3. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
  4. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  5. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  6. Create a virtual network link from the Private DNS zone to the required VNet and enable auto-registration only when that VNet should register VM host records.

Correct answers: A, C

Why: 2.1.7: This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to create and configure a virtual network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.7: Create and configure a virtual network gateway.

B: Not selected. This directly satisfies the requirement to monitor and troubleshoot networks by using Azure Monitor for Networks. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.3, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.

C: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.

D: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.

E: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.

F: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.7, 2.1.8.

Learning point: AZ700-21-Q190: Create the VPN virtual network gateway in GatewaySubnet with the required VPN type, SKU, generation, availability settings, and BGP configuration. | Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.

Question 191

Northwind Health is reviewing a shared-services topology used by several application teams. Operators need evidence that identifies the failing hop or policy before they make a production network change. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must diagnose and resolve virtual network gateway connectivity issues; implement Azure Extended Network. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7191. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Control private-endpoint reachability with routing, DNS, NSGs where supported, and service-side public-network settings so only approved private clients can reach the resource.
  2. Configure listeners with the correct frontend IP, port, protocol, host name, and certificate settings so requests match the intended site before routing rules are evaluated.
  3. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  4. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  5. Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway.
  6. Implement the Azure networking capability named in the requirement using the supported Microsoft configuration, validate prerequisites and dependencies, and confirm the result with Azure-native diagnostics before production rollout.

Correct answers: D, E

Why: 2.1.8: This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure access to private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.

B: Not selected. This directly satisfies the requirement to configure listeners. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.6, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.

C: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.

D: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.

E: Correct. This directly satisfies the requirement to diagnose and resolve virtual network gateway connectivity issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.8: Diagnose and resolve virtual network gateway connectivity issues.

F: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.8, 2.1.9.

Learning point: AZ700-21-Q191: Validate gateway and connection status, shared keys, IKE/IPsec proposals, BGP or prefix advertisements, effective routes, and on-premises firewall/NAT before redeploying the gateway. | Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.

Question 192

City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Azure Extended Network. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7192. Which recommendation most directly meets the requirement? Select one answer.

  1. Choose Azure-provided DNS, Azure Private DNS, or custom DNS based on the namespace and hybrid requirements, and ensure private names resolve to private addresses from every required VNet.
  2. Use WAF to protect HTTP(S) applications against common application-layer attacks with managed and custom rules; do not treat it as a replacement for NSGs or a general network firewall.
  3. Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.
  4. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  5. Host the public authoritative zone in Azure DNS, delegate the domain from the registrar with the Azure DNS name servers, and manage public record sets there.

Correct answer: C

Why: 2.1.9: This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

B: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.1, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

C: Correct. This directly satisfies the requirement to implement Azure Extended Network. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.9: Implement Azure Extended Network.

D: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

E: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.1.9.

Learning point: AZ700-21-Q192: Use Azure Extended Network only for the supported migration case that needs to stretch an on-premises subnet into Azure temporarily, while planning to remove the extension after migration.

Question 193

Northwind Health is reviewing a hybrid environment linked to two datacenters. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must design a site-to-site VPN connection, including for high availability. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7193. Which recommendation most directly meets the requirement? Select one answer.

  1. Select Firewall Basic, Standard, or Premium based on throughput and required features such as TLS inspection, IDPS, URL filtering, and advanced threat protection, not solely on cost.
  2. Deploy Azure Firewall into AzureFirewallSubnet or the secured Virtual WAN hub, assign the required public/private IP configuration, apply policy, and update route tables so inspected flows traverse it symmetrically.
  3. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  4. Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.
  5. Delegate the target subnet to the required Azure platform service and ensure the subnet meets that service’s delegation and coexistence constraints.

Correct answer: D

Why: 2.1.1: This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

B: Not selected. This directly satisfies the requirement to create and implement an Azure Firewall deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

C: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

D: Correct. This directly satisfies the requirement to design a site-to-site VPN connection, including for high availability. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.1: Design a site-to-site VPN connection, including for high availability.

E: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.1.1.

Learning point: AZ700-21-Q193: Design redundant site-to-site VPN paths with compatible active-active or dual-device topology, independent on-premises endpoints, and routing that can fail over without manual intervention.

Question 194

City Power & Light is reviewing a shared-services topology used by several application teams. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the hybrid connectivity team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7194. Which recommendation most directly meets the requirement? Select one answer.

  1. Associate the WAF policy to the correct Front Door security policy or Application Gateway scope and verify that requests traverse the protected listener/domain where the policy is enforced.
  2. Onboard the organization-owned public range as a Custom IP Prefix, complete Microsoft validation and provisioning, and then allocate public IP prefixes or addresses from the BYOIP range.
  3. Deploy Azure Route Server in its required dedicated subnet and establish BGP sessions with supported NVAs so dynamic routes are exchanged without maintaining large UDR sets.
  4. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.
  5. Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Correct answer: E

Why: 2.1.2: This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

B: Not selected. This directly satisfies the requirement to plan and implement a Custom IP address prefix (bring your own IP). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

C: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

D: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.2.

E: Correct. This directly satisfies the requirement to select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.2: Select an appropriate virtual network gateway stock-keeping unit (SKU) for site-to-site VPN requirements.

Learning point: AZ700-21-Q194: Select the VPN gateway SKU that meets required aggregate throughput, tunnel count, availability-zone, and feature requirements rather than sizing only for today’s traffic.

Question 195

Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Connectivity must remain available during a single tunnel or gateway-path failure while preserving authenticated private access. The network engineer must implement a site-to-site VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the application delivery team. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7195. Which recommendation most directly meets the requirement? Select one answer.

  1. Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.
  2. Choose Azure Front Door when users need a global HTTP(S) entry point with edge acceleration and resilient multi-region routing rather than a region-bound Layer 7 gateway.
  3. Select the supported Standard SKU/tier and regional or global design based on zone resiliency, scale, cross-region requirements, and backend resource compatibility.
  4. Use dedicated subnets when a service requires delegation, special routing, or isolation; share only where supported and where policy and scale requirements are compatible.
  5. Use Network Watcher IP flow verify with the VM, NIC, direction, protocol, addresses, and ports to identify the effective allow/deny decision and the specific NSG rule responsible.

Correct answer: A

Why: 2.1.3: This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Correct. This directly satisfies the requirement to implement a site-to-site VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.3: Implement a site-to-site VPN connection.

B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

C: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

D: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

E: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.1.3.

Learning point: AZ700-21-Q195: Configure the Azure VPN gateway, local network gateway, shared security parameters, and on-premises VPN device so both sides use compatible routes and IPsec/IKE settings.

Question 196

City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must identify when to use a policy-based VPN versus a route-based VPN connection. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the security engineering lead. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7196. Which recommendation most directly meets the requirement? Select one answer.

  1. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  2. Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.
  3. Advertise or configure a default route toward the required NVA, VPN, or ExpressRoute path and verify return routing so internet-bound traffic is forced through the inspection point without asymmetry.
  4. Use Microsoft Defender for Cloud Secure Score recommendations to prioritize network hardening items by exposure, impact, and remediation value instead of treating every finding equally.
  5. Use Network Watcher tools such as Connection troubleshoot, IP flow verify, next hop, packet capture, and Connection Monitor to isolate connectivity failures before changing security or routing.

Correct answer: B

Why: 2.1.4: This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

B: Correct. This directly satisfies the requirement to identify when to use a policy-based VPN versus a route-based VPN connection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.4: Identify when to use a policy-based VPN versus a route-based VPN connection.

C: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

E: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 2.1.4.

Learning point: AZ700-21-Q196: Prefer route-based VPN for modern Azure scenarios and dynamic routing; use policy-based VPN only when the peer requires policy selectors and the Azure limitations are acceptable.

Question 197

Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must create and configure a local network gateway; create and configure an IPsec/Internet Key Exchange (IKE) policy. The design must avoid overlapping address space and asymmetric routing, and the decision will be reviewed by the cloud architecture board. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7197. Which TWO recommendations should be implemented together? Select TWO answers.

  1. Start or validate in Detection mode to observe matches and tune exclusions, then move to Prevention mode when the policy is ready to block malicious requests without unacceptable false positives.
  2. Use Azure Traffic Manager for DNS-based global traffic distribution when endpoints can be public and the design needs priority, performance, weighted, geographic, or subnet routing.
  3. Peer VNets with nonoverlapping address spaces, configure forwarded-traffic and gateway options only as required, and validate effective routes on both sides.
  4. Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection.
  5. Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.
  6. Use the Microsoft-recommended private DNS zone for the service, link it to consuming VNets, and ensure hybrid DNS forwards the private namespace so the public FQDN resolves to the private endpoint address for authorized clients.

Correct answers: D, E

Why: 2.1.5: This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.1.6: This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.

Option review:

A: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

B: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

C: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

D: Correct. This directly satisfies the requirement to create and configure a local network gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.5: Create and configure a local network gateway.

E: Correct. This directly satisfies the requirement to create and configure an IPsec/Internet Key Exchange (IKE) policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.1.6: Create and configure an IPsec/Internet Key Exchange (IKE) policy.

F: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.1.5, 2.1.6.

Learning point: AZ700-21-Q197: Define the local network gateway with the on-premises VPN device public IP and the correct on-premises address prefixes or BGP settings, then reference it from the connection. | Configure a custom IPsec/IKE policy only when interoperability or security requirements demand it, and make encryption, integrity, DH/PFS, and lifetime settings compatible on both peers.

img