Microsoft AZ-700 Design, Implement, And Manage Azure ExpressRoute Practice Test
AZ-700 skill 2.3 | 46 original questions
This AZ-700 practice set focuses on design, implement, and manage azure expressroute through original scenario-based questions aligned to Microsoft skills measured as of July 27, 2026. The set is mapped to every official objective leaf assigned to this skill area. For broader exam preparation, review the Microsoft AZ-700 Exam Dumps page.
Instructions: Follow the selection count stated in each question. Review the rationale after answering. Every option includes a brief explanation of why it is or is not selected for the stated scenario.
City Power & Light is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an ExpressRoute connectivity model; select an appropriate ExpressRoute SKU and tier; design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7230. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: C, E, F
Why: 2.3.1: This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.3: This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2, 2.3.3.
B: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2, 2.3.3.
C: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
D: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2, 2.3.3.
E: Correct. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.1: Select an ExpressRoute connectivity model.
F: Correct. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.3: Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery.
Learning point: AZ700-23-Q230: Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct. | Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features. | Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an appropriate ExpressRoute SKU and tier. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7231. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
B: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
C: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
D: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
E: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
Learning point: AZ700-23-Q231: Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7232. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.3.3: This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
B: Correct. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.3: Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery.
C: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
D: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
E: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
Learning point: AZ700-23-Q232: Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7233. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.3.4: This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
B: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
C: Correct. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.4: Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct.
D: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
E: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
Learning point: AZ700-23-Q233: Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must choose between Azure private peering only, Microsoft peering only, or both. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7234. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.3.5: This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
B: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
C: Not selected. This directly satisfies the requirement to plan and configure subnet delegation. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
D: Correct. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.5: Choose between Azure private peering only, Microsoft peering only, or both.
E: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
Learning point: AZ700-23-Q234: Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.
Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Azure private peering; configure Microsoft peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7235. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, C
Why: 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.7: This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.7: Configure Microsoft peering.
B: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7.
C: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
D: Not selected. This directly satisfies the requirement to plan and implement network segmentation and address spaces. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7.
E: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7.
F: Not selected. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7.
Learning point: AZ700-23-Q235: Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets. | Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Microsoft peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7236. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.3.7: This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
C: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
D: Not selected. This directly satisfies the requirement to create and implement Azure Firewall Manager policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.6, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
E: Correct. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.7: Configure Microsoft peering.
Learning point: AZ700-23-Q236: Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must create and configure an ExpressRoute gateway. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7237. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.3.8: This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.8: Create and configure an ExpressRoute gateway.
B: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
C: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
D: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
E: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
Learning point: AZ700-23-Q237: Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must connect a virtual network to an ExpressRoute circuit. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7238. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.3.9: This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
B: Correct. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.9: Connect a virtual network to an ExpressRoute circuit.
C: Not selected. This directly satisfies the requirement to create and configure inbound NAT rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.10, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
D: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
Learning point: AZ700-23-Q238: Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must recommend a route advertisement configuration; configure encryption over ExpressRoute; implement Bidirectional Forwarding Detection. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7239. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: B, D, F
Why: 2.3.10: This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.11: This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure NAT Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.9, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11, 2.3.12.
B: Correct. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.11: Configure encryption over ExpressRoute.
C: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11, 2.3.12.
D: Correct. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.10: Recommend a route advertisement configuration.
E: Not selected. This directly satisfies the requirement to monitor and troubleshoot network health by using Azure Network Watcher. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.2, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11, 2.3.12.
F: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
Learning point: AZ700-23-Q239: Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes. | Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted. | Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure encryption over ExpressRoute; implement Bidirectional Forwarding Detection. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7240. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, E
Why: 2.3.11: This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12.
B: Correct. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.11: Configure encryption over ExpressRoute.
C: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12.
D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12.
E: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
F: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12.
Learning point: AZ700-23-Q240: Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted. | Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Bidirectional Forwarding Detection. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7241. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure an Azure Front Door, including routing, origins, and endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
C: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
D: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
E: Not selected. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
Learning point: AZ700-23-Q241: Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
City Power & Light is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must diagnose and resolve ExpressRoute connection issues. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7242. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.3.13: This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
B: Not selected. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
C: Not selected. This directly satisfies the requirement to link a private DNS zone to a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.6, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
D: Correct. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.13: Diagnose and resolve ExpressRoute connection issues.
E: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
Learning point: AZ700-23-Q242: Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an ExpressRoute connectivity model; select an appropriate ExpressRoute SKU and tier. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7243. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, E
Why: 2.3.1: This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
B: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
C: Correct. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.1: Select an ExpressRoute connectivity model.
D: Not selected. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
E: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
F: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
Learning point: AZ700-23-Q243: Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct. | Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an appropriate ExpressRoute SKU and tier. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7244. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
B: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
C: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
D: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
E: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
Learning point: AZ700-23-Q244: Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7245. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.3.3: This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.3: Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery.
B: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
C: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
D: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
E: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.3.3.
Learning point: AZ700-23-Q245: Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7246. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.3.4: This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
B: Correct. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.4: Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct.
C: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
D: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.4.
Learning point: AZ700-23-Q246: Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
Northwind Health is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must choose between Azure private peering only, Microsoft peering only, or both; configure Azure private peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7247. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, E
Why: 2.3.5: This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
C: Correct. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.5: Choose between Azure private peering only, Microsoft peering only, or both.
D: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
E: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
F: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
Learning point: AZ700-23-Q247: Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains. | Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must configure Azure private peering; configure Microsoft peering; create and configure an ExpressRoute gateway. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7248. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: C, D, E
Why: 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.7: This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.8: This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.1, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7, 2.3.8.
B: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7, 2.3.8.
C: Correct. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.7: Configure Microsoft peering.
D: Correct. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.8: Create and configure an ExpressRoute gateway.
E: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
F: Not selected. This directly satisfies the requirement to configure detection or prevention mode. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.3, but it does not directly satisfy the scenario requirement mapped to 2.3.6, 2.3.7, 2.3.8.
Learning point: AZ700-23-Q248: Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets. | Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit. | Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Microsoft peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7249. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.3.7: This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to integrate Private Link and Private Endpoint with DNS. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.5, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
B: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
C: Correct. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.7: Configure Microsoft peering.
D: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
E: Not selected. This directly satisfies the requirement to design private DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.4, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
Learning point: AZ700-23-Q249: Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must create and configure an ExpressRoute gateway. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7250. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.3.8: This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose when to use a public IP address prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
B: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
C: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
D: Correct. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.8: Create and configure an ExpressRoute gateway.
E: Not selected. This directly satisfies the requirement to implement and manage virtual network security by using Azure Virtual Network Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.10, but it does not directly satisfy the scenario requirement mapped to 2.3.8.
Learning point: AZ700-23-Q250: Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must connect a virtual network to an ExpressRoute circuit; recommend a route advertisement configuration. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7251. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, C
Why: 2.3.9: This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.10: This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.9, 2.3.10.
B: Correct. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.10: Recommend a route advertisement configuration.
C: Correct. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.9: Connect a virtual network to an ExpressRoute circuit.
D: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 2.3.9, 2.3.10.
E: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.9, 2.3.10.
F: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.9, 2.3.10.
Learning point: AZ700-23-Q251: Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes. | Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must recommend a route advertisement configuration; configure encryption over ExpressRoute; implement Bidirectional Forwarding Detection. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7252. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: A, B, C
Why: 2.3.10: This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.11: This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
B: Correct. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.11: Configure encryption over ExpressRoute.
C: Correct. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.10: Recommend a route advertisement configuration.
D: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11, 2.3.12.
E: Not selected. This directly satisfies the requirement to diagnose and resolve routing issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.7, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11, 2.3.12.
F: Not selected. This directly satisfies the requirement to map requirements to features and capabilities of WAF. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.1, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11, 2.3.12.
Learning point: AZ700-23-Q252: Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes. | Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted. | Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must configure encryption over ExpressRoute; implement Bidirectional Forwarding Detection; diagnose and resolve ExpressRoute connection issues. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 1:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7253. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: A, B, E
Why: 2.3.11: This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.13: This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.13: Diagnose and resolve ExpressRoute connection issues.
B: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
C: Not selected. This directly satisfies the requirement to create an application security group (ASG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.3, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12, 2.3.13.
D: Not selected. This directly satisfies the requirement to associate a NSG to a subnet or network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12, 2.3.13.
E: Correct. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.11: Configure encryption over ExpressRoute.
F: Not selected. This directly satisfies the requirement to associate an ASG to a network interface. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.11, 2.3.12, 2.3.13.
Learning point: AZ700-23-Q253: Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted. | Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence. | Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Bidirectional Forwarding Detection. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 4:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7254. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create and configure explicit outbound rules, including source network address translation (SNAT). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.11, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
B: Not selected. This directly satisfies the requirement to choose an Azure Load Balancer SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.3, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
C: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
D: Not selected. This directly satisfies the requirement to plan and configure shared or dedicated subnets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.5, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
E: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
Learning point: AZ700-23-Q254: Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must diagnose and resolve ExpressRoute connection issues. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 7:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7255. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.3.13: This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.13: Diagnose and resolve ExpressRoute connection issues.
B: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
C: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
D: Not selected. This directly satisfies the requirement to design service chaining, including gateway transit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.1, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
E: Not selected. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
Learning point: AZ700-23-Q255: Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an ExpressRoute connectivity model. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 10:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7256. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.3.1: This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure caching. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.1.
B: Correct. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.1: Select an ExpressRoute connectivity model.
C: Not selected. This directly satisfies the requirement to choose between regional and cross-region load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.5, but it does not directly satisfy the scenario requirement mapped to 2.3.1.
D: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 2.3.1.
E: Not selected. This directly satisfies the requirement to design and implement Azure DNS Private Resolver. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.7, but it does not directly satisfy the scenario requirement mapped to 2.3.1.
Learning point: AZ700-23-Q256: Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an appropriate ExpressRoute SKU and tier; design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 13:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7257. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, F
Why: 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.3: This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
B: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.2, 2.3.3.
C: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.3.2, 2.3.3.
D: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 2.3.2, 2.3.3.
E: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.2, 2.3.3.
F: Correct. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.3: Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery.
Learning point: AZ700-23-Q257: Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features. | Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery; design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 16:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7258. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, E
Why: 2.3.3: This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.4: This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.3: Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery.
B: Not selected. This directly satisfies the requirement to configure Azure Firewall rules. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.5, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
C: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
D: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
E: Correct. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.4: Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct.
F: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
Learning point: AZ700-23-Q258: Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure. | Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct; choose between Azure private peering only, Microsoft peering only, or both. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 19:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7259. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, E
Why: 2.3.4: This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.5: This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5.
B: Not selected. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5.
C: Correct. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.4: Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct.
D: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5.
E: Correct. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.5: Choose between Azure private peering only, Microsoft peering only, or both.
F: Not selected. This directly satisfies the requirement to associate a route table with a subnet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.5, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5.
Learning point: AZ700-23-Q259: Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required. | Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.
City Power & Light is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must choose between Azure private peering only, Microsoft peering only, or both. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 22:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7260. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.3.5: This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to activate and monitor distributed denial-of-service (DDoS) protection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.4, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
B: Not selected. This directly satisfies the requirement to configure TLS termination and end-to-end TLS encryption. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.5, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
C: Correct. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.5: Choose between Azure private peering only, Microsoft peering only, or both.
D: Not selected. This directly satisfies the requirement to implement a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
E: Not selected. This directly satisfies the requirement to configure service endpoint policies. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.5.
Learning point: AZ700-23-Q260: Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Azure private peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 2:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7261. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
B: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
C: Not selected. This directly satisfies the requirement to create service endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
D: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
E: Not selected. This directly satisfies the requirement to design a WAF deployment. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
Learning point: AZ700-23-Q261: Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Microsoft peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 5:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7262. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.3.7: This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
B: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
C: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
D: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
E: Correct. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.7: Configure Microsoft peering.
Learning point: AZ700-23-Q262: Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must create and configure an ExpressRoute gateway; connect a virtual network to an ExpressRoute circuit. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 8:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7263. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: C, F
Why: 2.3.8: This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.9: This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 2.3.8, 2.3.9.
B: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Front Door. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.8, 2.3.9.
C: Correct. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.9: Connect a virtual network to an ExpressRoute circuit.
D: Not selected. This directly satisfies the requirement to design and implement user-defined routes (UDRs). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.4, but it does not directly satisfy the scenario requirement mapped to 2.3.8, 2.3.9.
E: Not selected. This directly satisfies the requirement to plan private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.8, 2.3.9.
F: Correct. This directly satisfies the requirement to create and configure an ExpressRoute gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.8: Create and configure an ExpressRoute gateway.
Learning point: AZ700-23-Q263: Create the ExpressRoute virtual network gateway in GatewaySubnet with the SKU and resiliency model required for the circuit bandwidth and feature set. | Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must connect a virtual network to an ExpressRoute circuit. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 11:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7264. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.3.9: This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to connect a virtual network to an ExpressRoute circuit. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.9: Connect a virtual network to an ExpressRoute circuit.
B: Not selected. This directly satisfies the requirement to design public DNS zones. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
C: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
D: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
E: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.9.
Learning point: AZ700-23-Q264: Create the VNet-to-ExpressRoute connection between the ExpressRoute gateway and the provisioned circuit, then validate learned and advertised routes.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must recommend a route advertisement configuration; configure encryption over ExpressRoute. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 14:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7265. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: D, E
Why: 2.3.10: This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.11: This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement VNet peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.2, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11.
B: Not selected. This directly satisfies the requirement to implement Azure Traffic Manager. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11.
C: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11.
D: Correct. This directly satisfies the requirement to recommend a route advertisement configuration. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.10: Recommend a route advertisement configuration.
E: Correct. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.11: Configure encryption over ExpressRoute.
F: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.10, 2.3.11.
Learning point: AZ700-23-Q265: Advertise only the intended, nonoverlapping prefixes through BGP, summarize where safe, and use route filters or communities on Microsoft peering rather than leaking unrelated routes. | Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
City Power & Light is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must configure encryption over ExpressRoute. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 17:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7266. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.3.11: This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to verify IP flow. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.8, but it does not directly satisfy the scenario requirement mapped to 2.3.11.
B: Correct. This directly satisfies the requirement to configure encryption over ExpressRoute. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.11: Configure encryption over ExpressRoute.
C: Not selected. This directly satisfies the requirement to plan and implement network segmentation and address spaces. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.11.
D: Not selected. This directly satisfies the requirement to choose between manual and autoscale. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.3, but it does not directly satisfy the scenario requirement mapped to 2.3.11.
E: Not selected. This directly satisfies the requirement to create a public IP address. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.9, but it does not directly satisfy the scenario requirement mapped to 2.3.11.
Learning point: AZ700-23-Q266: Use supported IPsec over Microsoft peering or MACsec on ExpressRoute Direct, depending on the encryption boundary and circuit type, instead of assuming private peering is inherently encrypted.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must implement Bidirectional Forwarding Detection. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 20:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7267. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: C
Why: 2.3.12: This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure Transport Layer Security (TLS). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.9, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
B: Not selected. This directly satisfies the requirement to choose an appropriate tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.3, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
C: Correct. This directly satisfies the requirement to implement Bidirectional Forwarding Detection. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.12: Implement Bidirectional Forwarding Detection.
D: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud Secure Score. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.5, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.12.
Learning point: AZ700-23-Q267: Enable BFD on supported ExpressRoute peering to detect path failures faster than standard BGP timers and accelerate convergence.
City Power & Light is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must diagnose and resolve ExpressRoute connection issues. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 23:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7268. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: D
Why: 2.3.13: This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
B: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
C: Not selected. This directly satisfies the requirement to configure rule sets for WAF on Application Gateway. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.5, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
D: Correct. This directly satisfies the requirement to diagnose and resolve ExpressRoute connection issues. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.13: Diagnose and resolve ExpressRoute connection issues.
E: Not selected. This directly satisfies the requirement to configure forced tunneling. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.6, but it does not directly satisfy the scenario requirement mapped to 2.3.13.
Learning point: AZ700-23-Q268: Check circuit/provider provisioning, peering/BGP state, gateway health, route advertisements, FastPath eligibility, and effective routes to isolate the failing ExpressRoute segment.
Northwind Health is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an ExpressRoute connectivity model; select an appropriate ExpressRoute SKU and tier. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 3:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7269. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, E
Why: 2.3.1: This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a Public IP Prefix. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
B: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
C: Not selected. This directly satisfies the requirement to choose when to use a service endpoint. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.2.1, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
D: Not selected. This directly satisfies the requirement to configure health probes. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.5, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
E: Correct. This directly satisfies the requirement to select an ExpressRoute connectivity model. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.1: Select an ExpressRoute connectivity model.
F: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.1, 2.3.2.
Learning point: AZ700-23-Q269: Select the ExpressRoute connectivity model that matches the provider and physical topology: cloud exchange colocation, point-to-point Ethernet, any-to-any IPVPN, or ExpressRoute Direct. | Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
City Power & Light is reviewing a migration wave that must coexist with legacy routing for six months. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must select an appropriate ExpressRoute SKU and tier. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 6:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7270. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: E
Why: 2.3.2: This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to create a backend pool. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.4, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
B: Not selected. This directly satisfies the requirement to evaluate network security recommendations identified by Microsoft Defender for Cloud attack path analysis. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.6, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
C: Not selected. This directly satisfies the requirement to configure DNS settings for a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
D: Not selected. This directly satisfies the requirement to create private endpoints. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.2.
E: Correct. This directly satisfies the requirement to select an appropriate ExpressRoute SKU and tier. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.2: Select an appropriate ExpressRoute SKU and tier.
Learning point: AZ700-23-Q270: Choose the ExpressRoute SKU and bandwidth/tier that meet geographic reach, route-scale, FastPath/Direct requirements, and expected throughput without paying for unsupported features.
Northwind Health is reviewing a hybrid environment linked to two datacenters. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The network engineer must design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery; design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 9:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7271. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: B, E
Why: 2.3.3: This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.4: This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to identify appropriate use cases for Azure Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
B: Correct. This directly satisfies the requirement to design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.3: Design and implement ExpressRoute to meet requirements, including cross-region connectivity, redundancy, and disaster recovery.
C: Not selected. This directly satisfies the requirement to configure HTTP settings. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.8, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
D: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
E: Correct. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.4: Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct.
F: Not selected. This directly satisfies the requirement to select an appropriate Azure Firewall SKU. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.2.2, but it does not directly satisfy the scenario requirement mapped to 2.3.3, 2.3.4.
Learning point: AZ700-23-Q271: Use redundant ExpressRoute circuits/peerings and appropriately resilient gateways, with cross-region or disaster-recovery routing designed so a single circuit, provider edge, or region does not become a single point of failure. | Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required.
City Power & Light is reviewing a shared-services topology used by several application teams. Traffic reaches the destination on one path but returns on another, producing intermittent connectivity and inspection bypass. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct; choose between Azure private peering only, Microsoft peering only, or both; configure Azure private peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the security engineering lead. Change window 12:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7272. Which THREE recommendations should be implemented together? Select THREE answers.
Correct answers: B, C, E
Why: 2.3.4: This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.5: This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to configure rewrite rule sets. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.2.10, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5, 2.3.6.
B: Correct. This directly satisfies the requirement to design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.4: Design and implement ExpressRoute options, including Global Reach, FastPath, and ExpressRoute Direct.
C: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
D: Not selected. This directly satisfies the requirement to associate public IP addresses to resources. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.10, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5, 2.3.6.
E: Correct. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.5: Choose between Azure private peering only, Microsoft peering only, or both.
F: Not selected. This directly satisfies the requirement to create a network security group (NSG). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.1, but it does not directly satisfy the scenario requirement mapped to 2.3.4, 2.3.5, 2.3.6.
Learning point: AZ700-23-Q272: Use Global Reach for private site-to-site connectivity through Microsoft, FastPath to bypass the gateway data path where supported, and ExpressRoute Direct when dedicated Microsoft peering ports and very high bandwidth are required. | Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains. | Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
Northwind Health is reviewing a migration wave that must coexist with legacy routing for six months. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must choose between Azure private peering only, Microsoft peering only, or both; configure Azure private peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the cloud architecture board. Change window 15:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7273. Which TWO recommendations should be implemented together? Select TWO answers.
Correct answers: A, B
Why: 2.3.5: This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to choose between Azure private peering only, Microsoft peering only, or both. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.5: Choose between Azure private peering only, Microsoft peering only, or both.
B: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
C: Not selected. This directly satisfies the requirement to interpret virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.7, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
D: Not selected. This directly satisfies the requirement to implement virtual network flow logs. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.1.6, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
E: Not selected. This directly satisfies the requirement to create a virtual network (VNet). The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.1.2, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
F: Not selected. This directly satisfies the requirement to implement rules, URL rewrite, and URL redirect. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.3.8, but it does not directly satisfy the scenario requirement mapped to 2.3.5, 2.3.6.
Learning point: AZ700-23-Q273: Use Azure private peering for private VNet routes, Microsoft peering for supported Microsoft public services, or both when the requirements explicitly need both routing domains. | Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
City Power & Light is reviewing a hybrid environment linked to two datacenters. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Azure private peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the hybrid connectivity team. Change window 18:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7274. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: A
Why: 2.3.6: This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Correct. This directly satisfies the requirement to configure Azure private peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.6: Configure Azure private peering.
B: Not selected. This directly satisfies the requirement to associate a WAF policy. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 5.3.7, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
C: Not selected. This directly satisfies the requirement to identify network resources by using Cloud Security Explorer in Microsoft Defender for Cloud. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.4.7, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
D: Not selected. This directly satisfies the requirement to choose between public and internal load balancers. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
E: Not selected. This directly satisfies the requirement to implement a load balancing rule. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.9, but it does not directly satisfy the scenario requirement mapped to 2.3.6.
Learning point: AZ700-23-Q274: Configure Azure private peering with the provider using unique VLAN and /30 addressing plus BGP ASNs, then verify advertised private prefixes before attaching VNets.
Northwind Health is reviewing a shared-services topology used by several application teams. The architecture review found that the current network implementation does not meet a documented availability, security, or operability requirement. The network engineer must configure Microsoft peering. The design must retain troubleshooting evidence for incident review, and the decision will be reviewed by the application delivery team. Change window 21:00 UTC; validation must include evidence from Azure-native diagnostics and ticket NET-7275. Which recommendation most directly meets the requirement? Select one answer.
Correct answer: B
Why: 2.3.7: This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption.
Option review:
A: Not selected. This directly satisfies the requirement to implement Gateway Load Balancer. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 3.1.8, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
B: Correct. This directly satisfies the requirement to configure Microsoft peering. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. This is mapped to objective 2.3.7: Configure Microsoft peering.
C: Not selected. This directly satisfies the requirement to create a Private Link service. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 4.1.4, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
D: Not selected. This directly satisfies the requirement to design and implement Azure Route Server. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.3.8, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
E: Not selected. This directly satisfies the requirement to design name resolution inside a VNet. The recommended design uses the Azure capability in its supported role, accounts for its key dependencies, and validates the effective network behavior rather than relying on an assumption. That action is relevant to objective 1.2.1, but it does not directly satisfy the scenario requirement mapped to 2.3.7.
Learning point: AZ700-23-Q275: Configure Microsoft peering with validated public prefixes, BGP, route filters for the required service communities, and provider-side VLAN/IP settings that match the circuit.
Popular posts
Recent Posts
